This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Scheduled Task Creation
Original Source:
[Sigma source]
Title:
Suspicious Scheduled Task Creation
Status:
test
Description:
Detects suspicious scheduled task creation events. Based on attributes such as paths, commands line flags, etc.
References:
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4698
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-12-05
modified:
2022-12-07
Tags:
-'attack.execution'
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1053.005'
Logsource:
product: windows
service: security
definition: The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data.
Detection:
selection_eid:
EventID
:
'4698'
selection_paths:
TaskContent|contains
:
-'\AppData\Local\Temp\'
-'\AppData\Roaming\'
-'\Users\Public\'
-'\WINDOWS\Temp\'
-'C:\Temp\'
-'\Desktop\'
-'\Downloads\'
-'\Temporary Internet'
-'C:\ProgramData\'
-'C:\Perflogs\'
selection_commands:
TaskContent|contains
:
-'regsvr32'
-'rundll32'
-'cmd.exe</Command>'
-'cmd</Command>'
-'<Arguments>/c '
-'<Arguments>/k '
-'<Arguments>/r '
-'powershell'
-'pwsh'
-'mshta'
-'wscript'
-'cscript'
-'certutil'
-'bitsadmin'
-'bash.exe'
-'bash '
-'scrcons'
-'wmic '
-'wmic.exe'
-'forfiles'
-'scriptrunner'
-'hh.exe'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high