Skip to content

Hide Navigation Hide TOC

Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE (81325ce1-be01-4250-944f-b4789644556f)

Detects Schtask creations that point to a suspicious folder or an environment variable often used by malware

Cluster A Galaxy A Cluster B Galaxy B Level
Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE (81325ce1-be01-4250-944f-b4789644556f) Sigma-Rules Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern 1
Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern 2