Scheduled task created

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

What happened

A scheduled task was created, potentially to establish persistence.

Goal

Detect the creation of scheduled tasks.

Strategy

This rule generates a signal when a scheduled task is created. Threat actors often use scheduled tasks as a persistence mechanism.

Triage and response

  1. Identify what the scheduled task is executing and determine if it’s authorized.
  2. If it’s not authorized, isolate the host from the network.
  3. Follow your organization’s internal processes for investigating and remediating compromised systems.

Requires Agent version 7.50.0 or greater.

PREVIEWING: cswatt/DOCS_10103_container_autoscaling