4355ece230
remove: Active Directory Kerberos DLL Loaded Via Office Application - deprecated as it triggers on normal activity fix: Scheduled Task Creation Via Schtasks.EXE - add for for msoffice application fix: Use Short Name Path in Command Line - add filter for dotnet csc.exe fix: Potential Product Reconnaissance Via Wmic.EXE - add filter for some product related operation through wmic fix: WMIC Remote Command Execution - fix broken FP filter fix: Classes Autorun Keys Modification - filter null details fix: CurrentVersion Autorun Keys Modification - filter null details fix: Modification of IE Registry Settings - filter null details fix: Potential Persistence Via Shim Database Modification - filter null details fix: Scheduled TaskCache Change by Uncommon Program - filter null details update: Copy From Or To Admin Share Or Sysvol Folder - some logic change --------- Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>
43 lines
1.6 KiB
YAML
43 lines
1.6 KiB
YAML
title: Scheduled Task Creation Via Schtasks.EXE
|
|
id: 92626ddd-662c-49e3-ac59-f6535f12d189
|
|
status: test
|
|
description: Detects the creation of scheduled tasks by user accounts via the "schtasks" utility.
|
|
references:
|
|
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create
|
|
author: Florian Roth (Nextron Systems)
|
|
date: 2019-01-16
|
|
modified: 2025-10-22
|
|
tags:
|
|
- attack.execution
|
|
- attack.persistence
|
|
- attack.privilege-escalation
|
|
- attack.t1053.005
|
|
- attack.s0111
|
|
- car.2013-08-001
|
|
- stp.1u
|
|
logsource:
|
|
category: process_creation
|
|
product: windows
|
|
detection:
|
|
selection:
|
|
Image|endswith: '\schtasks.exe'
|
|
CommandLine|contains: ' /create '
|
|
filter_main_system_user:
|
|
User|contains: # covers many language settings
|
|
- 'AUTHORI'
|
|
- 'AUTORI'
|
|
filter_optional_msoffice:
|
|
# schtasks.exe /Create /tn "Microsoft\Office\Office Performance Monitor" /XML "C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_Office Performance Monitor.xml"
|
|
ParentImage:
|
|
- 'C:\Program Files\Microsoft Office\root\integration\integrator.exe'
|
|
- 'C:\Program Files (x86)\Microsoft Office\root\integration\integrator.exe'
|
|
Image:
|
|
- 'C:\Windows\System32\schtasks.exe'
|
|
- 'C:\Windows\SysWOW64\schtasks.exe'
|
|
CommandLine|contains: 'Microsoft\Office\Office Performance Monitor'
|
|
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
|
|
falsepositives:
|
|
- Administrative activity
|
|
- Software installation
|
|
level: low
|