You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A scheduled task was created in Windows or Azure. It is common for system administrators and approved software to create scheduled tasks, but adversaries are known to use them for persistence within a Windows environment. This rule is disabled by default due to the volume of events it can produce. Users should filter/exclude allowed scheduled tasks according to their environment before enabling the rule. The scheduled task name is logged in the "commandLine" field.
Additional Details
Detail
Value
Type
Templated Match
Category
Persistence
Apply Risk to Entities
device_hostname, device_ip, user_username
Signal Name
Windows - Scheduled Task Creation
Summary Expression
Detected scheduled trask creation on host: {{device_hostname}}