Skip to content

Hide Navigation Hide TOC

Suspicious Modification Of Scheduled Tasks (1c0e41cd-21bb-4433-9acc-4a2cd6367b9b)

Detects when an attacker tries to modify an already existing scheduled tasks to run from a suspicious location Attackers can create a simple looking task in order to avoid detection on creation as it's often the most focused on Instead they modify the task after creation to include their malicious payload

Cluster A Galaxy A Cluster B Galaxy B Level
Suspicious Modification Of Scheduled Tasks (1c0e41cd-21bb-4433-9acc-4a2cd6367b9b) Sigma-Rules Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2