Hunting Rituals #3: Threat hunting for scheduled tasks
ID: 07573ea8-58d8-5847-b8bc-2ee43c81d4a1
STIX ID: report--07573ea8-58d8-5847-b8bc-2ee43c81d4a1
Feed Name: Group-IB Blog
The report provides practical techniques for hunting Windows Scheduled Task persistence (T1053.005/T1053.002), including EDR queries for process creation involving schtasks.exe/at.exe, detecting execution via characteristic parent processes (taskeng.exe, taskhost.exe, svchost.exe with Schedule service), and locating/reviewing task XML files in \Windows\System32\Tasks\ to extract executed commands, while noting the need to filter benign noise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
