Important Scheduled Task Deleted/Disabled

 Original Source: [Sigma source]
Title: Important Scheduled Task Deleted/Disabled
Status: test
Description:Detects when adversaries stop services or processes by deleting or disabling their respective scheduled tasks in order to conduct data destructive activities
References:
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4699
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4701
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-05
modified:2023-03-13
Tags:
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1053.005'
Logsource:
  • product: windows
  • service: security
  • definition: The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data.
Detection:
  selection:
    EventID:
      -'4699'
      -'4701'

    TaskName|contains:
      -'\Windows\SystemRestore\SR'
      -'\Windows\Windows Defender\'
      -'\Windows\BitLocker'
      -'\Windows\WindowsBackup\'
      -'\Windows\WindowsUpdate\'
      -'\Windows\UpdateOrchestrator\Schedule'
      -'\Windows\ExploitGuard'

  filter_main_defender_update:
    EventID: '4699'
    SubjectUserName|endswith: '$'
    TaskName|contains: '\Windows\Windows Defender\'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high