title: Windows 10 Scheduled Task SandboxEscaper 0-day id: 931b6802-d6a6-4267-9ffa-526f57f22aaf status: experimental description: Detects Task Scheduler .job import arbitrary DACL write\par references: - https://github.com/SandboxEscaper/polarbearrepo/tree/master/bearlpe author: Olaf Hartong date: 2019/05/22 logsource: category: process_creation product: windows detection: selection: Image: schtasks.exe CommandLine: '*/change*/TN*/RU*/RP*' condition: selection falsepositives: - Unknown tags: - attack.privilege_escalation - attack.execution - attack.t1053 - car.2013-08-001 level: high