Files
blue-team-tools/rules/windows/file_event/file_event_susp_task_write.yml
T
2021-11-20 12:35:41 +01:00

27 lines
684 B
YAML

title: Suspicious Scheduled Task Writ to System32 Tasks
id: 80e1f67a-4596-4351-98f5-a9c3efabac95
status: experimental
description:
references:
- https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/
author: Florian Roth
date: 2021/11/16
tags:
- attack.persistence
- attack.execution
- attack.t1053
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains: '\Windows\System32\Tasks'
Image|contains:
- '\AppData\'
- 'C:\PerfLogs'
- '\Windows\System32\config\systemprofile'
condition: selection
falsepositives:
- Unknown
level: high