Suspicious Modification Of Scheduled Tasks (1c0e41cd-21bb-4433-9acc-4a2cd6367b9b)
Detects when an attacker tries to modify an already existing scheduled tasks to run from a suspicious location Attackers can create a simple looking task in order to avoid detection on creation as it's often the most focused on Instead they modify the task after creation to include their malicious payload