Skip to content

<<< Hide Navigation Hide TOC >>>

Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE (81325ce1-be01-4250-944f-b4789644556f)

Detects Schtask creations that point to a suspicious folder or an environment variable often used by malware

Galaxy ColorsSigma-Rule...Attack Pat...
Rows: 2
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE (81325ce1-be01-4250-944f-b4789644556f) Sigma-Rules Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2