Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)
ID: 7be6dd4d-7a26-5dd3-9ab8-f43b5f59af65
STIX ID: report--7be6dd4d-7a26-5dd3-9ab8-f43b5f59af65
Feed Name: Elastic Security Labs
Threat Score
This Elastic Security blog post reviews Windows persistence techniques—scheduled tasks (T1053) and BITS jobs (T1197)—illustrating real-world usage by threat actors (e.g., APT34, QBot) and providing practical detection/hunting guidance including EQL queries, relevant command-line indicators, PowerShell cmdlets, and recommended telemetry sources for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
