Skip to content

Hide Navigation Hide TOC

Persistence and Execution at Scale via GPO Scheduled Task (a8f29a7b-b137-4446-80a0-b804272f3da2)

Detect lateral movement using GPO scheduled task, usually used to deploy ransomware at scale

Cluster A Galaxy A Cluster B Galaxy B Level
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Persistence and Execution at Scale via GPO Scheduled Task (a8f29a7b-b137-4446-80a0-b804272f3da2) Sigma-Rules 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2