logo

Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)

ID: 7be6dd4d-7a26-5dd3-9ab8-f43b5f59af65

STIX ID: report--7be6dd4d-7a26-5dd3-9ab8-f43b5f59af65

Feed Name: Elastic Security Labs

Threat Score
65/100

Date Published: 2022-06-21

Date Updated: 2026-04-27

...
...

This Elastic Security blog post reviews Windows persistence techniques—scheduled tasks (T1053) and BITS jobs (T1197)—illustrating real-world usage by threat actors (e.g., APT34, QBot) and providing practical detection/hunting guidance including EQL queries, relevant command-line indicators, PowerShell cmdlets, and recommended telemetry sources for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.