Detect New Scheduled Task Creation that Run Executables From Non-Standard Location

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This hunting query identifies new scheduled task created, to run executables from uncommon location like temp folders. Malware often creates scheduled tasks to execute malicious code and maintain persistence on a system.

Attribute Value
Type Hunting Query
Solution Malware Protection Essentials
ID b43394b9-fa91-4d98-b331-619926a933bb
Tactics Execution, PrivilegeEscalation, Persistence
Techniques T1053
Required Connectors CrowdStrikeFalconEndpointProtection, MicrosoftThreatProtection, SentinelOne, VMwareCarbonBlack, CiscoSecureEndpoint, TrendMicroApexOne, TrendMicroApexOneAma
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Malware Protection Essentials