Skip to content

<<< Hide Navigation Hide TOC >>>

Scheduled Task Executing Encoded Payload from Registry (c4eeeeae-89f4-43a7-8b48-8d1bdfa66c78)

Detects the creation of a schtask that potentially executes a base64 encoded payload stored in the Windows Registry using PowerShell.