Rule Info
Name
Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
Author
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
Description
Detects the creation of a schedule task that runs weekly and execute the "shutdown /l /f" command.
This behavior was observed being used by KamiKakaBot samples in order to achieve persistence on a system.
Date
2024-03-22 00:00:00
Modified
None
Id
fe9e8ba9-4419-41e6-a574-bd9f7b3af961
Tags
attack.persistence detection.emerging-threats DEMO
Type
Community Rule
Link to Public Repo