title: Scheduled Task Creation status: experimental description: Detects the creation of scheduled tasks in user session author: Florian Roth logsource: category: process_creation product: windows detection: selection: Image: '*\schtasks.exe' CommandLine: '* /create *' filter: User: NT AUTHORITY\SYSTEM condition: selection and not filter fields: - CommandLine - ParentCommandLine tags: - attack.execution - attack.persistence - attack.privilege_escalation - attack.t1053 - attack.s0111 - car.2013-08-001 falsepositives: - Administrative activity - Software installation level: low