Skip to content

Hide Navigation Hide TOC

Scheduled Task Executed From A Suspicious Location (424273ea-7cf8-43a6-b712-375f925e481f)

Detects the execution of Scheduled Tasks where the Program being run is located in a suspicious location or it's an unusale program to be run from a Scheduled Task

Cluster A Galaxy A Cluster B Galaxy B Level
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task Executed From A Suspicious Location (424273ea-7cf8-43a6-b712-375f925e481f) Sigma-Rules 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2