Tag
high
advisory
Detection of Scheduled Tasks Created with SYSTEM Privileges
1 rule 1 TTPAdversaries often leverage Windows scheduled tasks to establish persistence or execute code with NT AUTHORITY\SYSTEM privileges, a technique commonly observed in various malware campaigns.
persistence
privilege-escalation
windows
schtasks
1r
1t
high
advisory
Suspicious Task Scheduling via Schtasks
1 rule 1 TTPDetection of potentially malicious scheduled task creation or modification using specific trigger types that often bypass standard administrative activity monitoring.
persistence
windows
schtasks
1r
1t
medium
advisory
Schtasks Run Task On Demand
2 rules 1 TTPDetection of on-demand execution of Windows Scheduled Tasks via the schtasks.exe command-line utility, a common technique for persistence and lateral movement.
Splunk Enterprise +2
schtasks
scheduled-task
persistence
execution
2r
1t