For the complete documentation index, see llms.txt. This page is also available as Markdown.

An unsigned process created scheduled task and performed an injection

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

4 Hours

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Scheduled tasks Analytics

ATT&CK Tactic

Persistence (TA0003), Defense Evasion (TA0005)

ATT&CK Technique

Scheduled Task/Job: Scheduled Task (T1053.005), Process Injection (T1055)

Severity

Medium

Description

An unsigned process created scheduled task and performed an injection.

Attacker's Goals

To ensure they have persistence on the system, the threat actor may use scheduled tasks to set persistence, Then, to avoid detection and carry out stealth execution, they may inject a malicious payload into a remote process.

Investigative actions

  • Investigate the injection payload and the injection process.

  • Check if the scheduled task trigger payload is malicious.

Variations

Possible an unsigned installer created scheduled task and performed an injection

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Defense Evasion (TA0005)

ATT&CK Technique

Scheduled Task/Job: Scheduled Task (T1053.005), Process Injection (T1055)

Severity

Low

Description

Possible an unsigned installer created scheduled task and performed an injection.

Attacker's Goals

To ensure they have persistence on the system, the threat actor may use scheduled tasks to set persistence, Then, to avoid detection and carry out stealth execution, they may inject a malicious payload into a remote process.

Investigative actions

  • Investigate the injection payload and the injection process.

  • Check if the scheduled task trigger payload is malicious.

Was this helpful?