Skip to content

Hide Navigation Hide TOC

Potential Persistence Via Microsoft Compatibility Appraiser (f548a603-c9f2-4c89-b511-b089f7e94549)

Detects manual execution of the "Microsoft Compatibility Appraiser" task via schtasks. In order to trigger persistence stored in the "\AppCompatFlags\TelemetryController" registry key.

Cluster A Galaxy A Cluster B Galaxy B Level
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Potential Persistence Via Microsoft Compatibility Appraiser (f548a603-c9f2-4c89-b511-b089f7e94549) Sigma-Rules 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2