Removal Of SD Value to Hide Schedule Task - Registry
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Remove SD (Security Descriptor) value in \\Schedule\\TaskCache\\Tree registry hive to hide schedule task. This technique is used by Tarrask malware
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "Registry entry deleted" AND ACCESSES = "DeleteKey" AND ((OBJECTNAME contains "\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree" AND OBJECTNAME contains "SD") OR (OBJECTNAME endswith "\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree" AND isExist(OBJECTVALUENAME))) select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.OBJECTNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Sittikorn S


