Analytics Medium

An unsigned process created scheduled task and performed an injection

An unsigned process created scheduled task and performed an injection.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Persistence (TA0003) Defense Evasion (TA0005)
ATT&CK techniques: Scheduled Task/Job: Scheduled Task (T1053.005) Process Injection (T1055)
Detector tags: Scheduled tasks Analytics
Attacker's goals:

To ensure they have persistence on the system, the threat actor may use scheduled tasks to set persistence, Then, to avoid detection and carry out stealth execution, they may inject a malicious payload into a remote process.

Investigative actions:

Investigate the injection payload and the injection process. Check if the scheduled task trigger payload is malicious.

Test period:
4 Hours
Deduplication:
1 Day
1 variation:
  • Possible an unsigned installer created scheduled task and performed an injection Low (parent: Medium)