Unsigned process creates a scheduled task via file access
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Scheduled tasks Analytics
ATT&CK Tactic
Execution (TA0002), Persistence (TA0003)
ATT&CK Technique
Scheduled Task/Job (T1053)
Severity
Low
Description
A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity.
Attacker's Goals
Attackers may attempt to gain persistence on the endpoint using scheduled tasks.
Investigative actions
Review the process executed by the schedule task.
Investigate the specific scheduled task execution chain.
Variations
PreviousUnsigned DLL Side-Loading
NextUnsigned process injecting into a Windows system binary with no command line
Was this helpful?
