Suspicious Schtasks Execution AppData Folder

 Original Source: [Sigma source]
Title: Suspicious Schtasks Execution AppData Folder
Status: test
Description:Detects the creation of a schtask that executes a file from C:\Users\<USER>\AppData\Local
References:
  -https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/
Author: pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-03-15
modified:2022-07-28
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1053.005'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    Image|endswith: '\schtasks.exe'
    CommandLine|contains|all:
      -'/Create'
      -'/RU'
      -'/TR'
      -'C:\Users\'
      -'\AppData\Local\'

    CommandLine|contains:
      -'NT AUT'
      -' SYSTEM '

  filter:
    ParentImage|contains|all:
      -'\AppData\Local\Temp\'
      -'TeamViewer_.exe'

    Image|endswith: '\schtasks.exe'
    CommandLine|contains: '/TN TVInstallRestore'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high