Analytics BIOC
Low
✕
Unsigned process creates a scheduled task via file access
A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
ATT&CK techniques: Scheduled Task/Job (T1053)
Detector tags: Scheduled tasks Analytics
Attacker's goals:
Attackers may attempt to gain persistence on the endpoint using scheduled tasks.
Investigative actions:
Review the process executed by the schedule task. Investigate the specific scheduled task execution chain.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unsigned process creates a scheduled task via file access on a sensitive server Medium (parent: Low)