Uncommon signed process execution by scheduled task
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Scheduled tasks Analytics
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Scheduled Task/Job (T1053)
Severity
Informational
Description
An uncommon process was executed by a scheduled task.
Attacker's Goals
Attackers may attempt to gain persistence, privilege escalation or proxy execution on the endpoint using scheduled tasks.
Investigative actions
Review the process executed by the schedule task.
Investigate the specific scheduled task execution chain.
Check if the vendor is known in the organization for creating scheduled tasks to execute his product.
Variations
PreviousUncommon SetWindowsHookEx API invocation of a possible keylogger
NextUncommon SQL like command line
Was this helpful?
