Tag
high
advisory
TelemetryController Scheduled Task Hijack for Persistence
2 rules 1 TTPThe rule detects the hijack of the Microsoft Compatibility Appraiser scheduled task to establish persistence with system integrity level, by monitoring CompatTelRunner.exe process execution and detecting unexpected child processes.
Microsoft Compatibility Appraiser +3
persistence
scheduled_task
telemetry
windows
2r
1t
medium
advisory
Scheduled Task Created or Deleted via Command Line
2 rules 2 TTPsDetection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.
Windows
persistence
privilege_escalation
scheduled_task
2r
2t
low
advisory
Suspicious Image Load (taskschd.dll) from MS Office
2 rules 2 TTPsDetection of taskschd.dll image loads from Microsoft Office applications indicates potential COM-based scheduled task creation for persistence, bypassing traditional schtasks.exe usage.
Word +4
persistence
execution
windows
image_load
scheduled_task
2r
2t
low
advisory
Suspicious Local Scheduled Task Creation
2 rules 1 TTPThis rule detects the creation of scheduled tasks on Windows systems by non-system accounts, a common technique used by adversaries for persistence, lateral movement, and privilege escalation.
Elastic Defend
persistence
windows
scheduled_task
attack.persistence
2r
1t