Scheduled Task hidden by registry modification
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Stealth (TA0005), Defense Impairment (TA0112)
ATT&CK Technique
Modify Registry (T1112), Hide Artifacts (T1564)
Severity
Low
Description
Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry.
Attacker's Goals
Adversaries may hide their malicious Scheduled Task to evade detection.
Investigative actions
Check the appropriate Scheduled Task to verify its legitimacy.
You can also check the executing executable to verify its purpose.
Was this helpful?
