Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
|
Detector Tags |
Impacket Analytics |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Response playbooks |
Description
A new rare scheduled task was created with a rare path and a rare command line.
Attacker's Goals
Attackers may attempt to gain persistence on the endpoint using scheduled task.
Investigative actions
- Review the action of the created scheduled task.
- Investigate the execution chain of the process creating the scheduled task.
Variations
Rare scheduled task created by an injected actorUncommon remote scheduled task created
Uncommon local scheduled task created
Highly rare scheduled task created