Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0441 — Detection of Suspicious Scheduled Task Creation and Execution on Windows
DET0441

Detection of Suspicious Scheduled Task Creation and Execution on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1221 Analytic 1221
Windows

Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.

WinEventLog:Security EventCode=4698 WinEventLog:Security EventCode=4702 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=13, 14
[TimeWindow] Defines threshold for grouping task creation and associated execution within suspicious time proximity.
[UserContext] Filters based on non-standard user accounts or execution under SYSTEM when not typical for the environment.
[TaskNamePattern] Allows defenders to flag obfuscated, randomized, or suspicious task names outside normal conventions.
[CommandLineEntropyThreshold] Flags tasks executing heavily obfuscated PowerShell or binary blobs via base64 or encoding.

Detected Techniques

1

Details

MITRE ID
DET0441
STIX ID
x-mitre-detection-strategy--c7bdd7d7-19dc-4042-8565-5e0cf4656102
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.