2017-03-17 07:41:27 +00:00
title : Rare Scheduled Task Creations
2019-11-12 22:12:27 +00:00
id : b20f6158-9438-41be-83da-a5a16ac90c2b
2017-03-17 07:41:27 +00:00
status : experimental
2020-06-16 20:46:08 +00:00
description : This rule detects rare scheduled task creations. Typically software gets installed on multiple systems and not only on a few. The aggregation and count function selects tasks with rare names.
2018-07-24 08:56:41 +00:00
tags :
2019-03-05 22:25:49 +00:00
- attack.persistence
2020-08-24 23:09:17 +00:00
- attack.t1053 # an old one
2018-07-24 08:56:41 +00:00
- attack.s0111
2020-06-16 20:46:08 +00:00
- attack.t1053.005
2017-03-17 07:41:27 +00:00
author : Florian Roth
2020-01-30 15:07:37 +00:00
date : 2017 /03/17
2017-03-17 07:41:27 +00:00
logsource :
product : windows
2017-03-17 15:09:31 +00:00
service : taskscheduler
2017-03-17 07:41:27 +00:00
detection :
selection :
EventID : 106
timeframe : 7d
2020-01-30 15:07:37 +00:00
condition : selection | count() by TaskName < 5
2017-03-17 07:41:27 +00:00
falsepositives :
- Software installation
level : low