2022-09-09 15:02:31 +02:00
title : Delete Important Scheduled Task
id : dbc1f800-0fe0-4bc0-9c66-292c2abe3f78
related :
2023-02-07 13:55:14 +01:00
- id : 9e3cb244-bdb8-4632-8c90-6079c8f4f16d # TaskScheduler EventLog
type : similar
- id : 7595ba94-cf3b-4471-aa03-4f6baa9e5fad # Security-Audting Eventlog
2023-01-13 17:21:21 +01:00
type : similar
2022-09-09 15:02:31 +02:00
status : experimental
2023-01-17 01:00:44 +01:00
description : Detects when adversaries stop services or processes by deleting their respective scheduled tasks in order to conduct data destructive activities
2022-09-09 15:02:31 +02:00
references :
- Internal Research
2023-02-01 11:14:59 +01:00
author : Nasreddine Bencherchali (Nextron Systems)
2022-09-09 15:02:31 +02:00
date : 2022 /09/09
2022-10-28 15:06:36 +02:00
tags :
- attack.impact
- attack.t1489
2022-09-09 15:02:31 +02:00
logsource :
category : process_creation
product : windows
detection :
schtasks_exe :
Image|endswith : '\schtasks.exe'
CommandLine|contains|all :
- '/delete'
- '/tn'
CommandLine|contains :
# Add more important tasks
- '\Windows\SystemRestore\SR'
- '\Windows\Windows Defender\'
- ' \Windows\BitLocker'
- '\Windows\WindowsBackup\'
- ' \Windows\WindowsUpdate\'
- '\Windows\UpdateOrchestrator\'
- ' \Windows\ExploitGuard'
condition : all of schtasks_*
falsepositives :
- Unlikely
level : high