Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.11 KB

MATCH-S00530.md

File metadata and controls

33 lines (26 loc) · 1.11 KB

Rules: Schtasks Used For Forcing A Reboot

Description

This rule looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled.

Additional Details

Detail Value
Type Templated Match
Category Execution
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Schtasks Used For Forcing A Reboot
Summary Expression Scheduled task used to force reboot on host: {{device_hostname}}
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTactic:TA0003, _mitreAttackTactic:TA0004, _mitreAttackTechnique:T1053, _mitreAttackTechnique:T1053.002, _mitreAttackTechnique:T1053.005

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema user_username