Analytics BIOC Low

Unsigned process creates a scheduled task via file access

A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Persistence (TA0003)
ATT&CK techniques: Scheduled Task/Job (T1053)
Detector tags: Scheduled tasks Analytics
Attacker's goals:

Attackers may attempt to gain persistence on the endpoint using scheduled tasks.

Investigative actions:

Review the process executed by the schedule task. Investigate the specific scheduled task execution chain.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unsigned process creates a scheduled task via file access on a sensitive server Medium (parent: Low)