This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Important Scheduled Task Deleted/Disabled
Original Source:
[Sigma source]
Title:
Important Scheduled Task Deleted/Disabled
Status:
test
Description:
Detects when adversaries stop services or processes by deleting or disabling their respective scheduled tasks in order to conduct data destructive activities
References:
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4699
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4701
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-12-05
modified:
2023-03-13
Tags:
-'attack.execution'
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1053.005'
Logsource:
product: windows
service: security
definition: The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data.
Detection:
selection:
EventID
:
-'4699'
-'4701'
TaskName|contains
:
-'\Windows\SystemRestore\SR'
-'\Windows\Windows Defender\'
-'\Windows\BitLocker'
-'\Windows\WindowsBackup\'
-'\Windows\WindowsUpdate\'
-'\Windows\UpdateOrchestrator\Schedule'
-'\Windows\ExploitGuard'
filter_main_defender_update:
EventID
:
'4699'
SubjectUserName|endswith
:
'$'
TaskName|contains
:
'\Windows\Windows Defender\'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high