Scheduled Task Executing Payload from Registry

 Original Source: [Sigma source]
Title: Scheduled Task Executing Payload from Registry
Status: test
Description:Detects the creation of a schtasks that potentially executes a payload stored in the Windows Registry using PowerShell.
References:
  -https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/
Author: X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2023-07-18
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1053.005'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\schtasks.exe' OriginalFileName:'schtasks.exe'   selection_cli_create:
    CommandLine|contains: '/Create'
  selection_cli_get:
    CommandLine|contains:
      -'Get-ItemProperty'
      -' gp '

  selection_cli_hive:
    CommandLine|contains:
      -'HKCU:'
      -'HKLM:'
      -'registry::'
      -'HKEY_'

  filter_main_encoding:
    CommandLine|contains:
      -'FromBase64String'
      -'encodedcommand'

  condition:all of selection_* and not 1 of filter_*
Falsepositives:
  -Unknown
Level: medium