Rule: Rare scheduled task installs

This commit is contained in:
Florian Roth 2017-03-17 08:41:27 +01:00
parent 3a7652fff9
commit e46ecd2aff

View File

@ -0,0 +1,15 @@
title: Rare Scheduled Task Creations
status: experimental
description:
author: Florian Roth
logsource:
product: windows
service: microsoft-windows-taskscheduler
detection:
selection:
EventID: 106
timeframe: 7d
condition: selection | count() by TaskName < 5
falsepositives:
- Software installation
level: low