Suspicious Scheduled Task Creation

 Original Source: [Sigma source]
Title: Suspicious Scheduled Task Creation
Status: test
Description:Detects suspicious scheduled task creation events. Based on attributes such as paths, commands line flags, etc.
References:
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4698
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-05
modified:2022-12-07
Tags:
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1053.005'
Logsource:
  • product: windows
  • service: security
  • definition: The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data.
Detection:
  selection_eid:
    EventID: '4698'
  selection_paths:
    TaskContent|contains:
      -'\AppData\Local\Temp\'
      -'\AppData\Roaming\'
      -'\Users\Public\'
      -'\WINDOWS\Temp\'
      -'C:\Temp\'
      -'\Desktop\'
      -'\Downloads\'
      -'\Temporary Internet'
      -'C:\ProgramData\'
      -'C:\Perflogs\'

  selection_commands:
    TaskContent|contains:
      -'regsvr32'
      -'rundll32'
      -'cmd.exe</Command>'
      -'cmd</Command>'
      -'<Arguments>/c '
      -'<Arguments>/k '
      -'<Arguments>/r '
      -'powershell'
      -'pwsh'
      -'mshta'
      -'wscript'
      -'cscript'
      -'certutil'
      -'bitsadmin'
      -'bash.exe'
      -'bash '
      -'scrcons'
      -'wmic '
      -'wmic.exe'
      -'forfiles'
      -'scriptrunner'
      -'hh.exe'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high