Detects remote RPC calls to create or execute a scheduled task via SASec
Detects remote RPC calls to create or execute a scheduled task via SASec
Detects remote RPC calls to create or execute a scheduled task
Detects remote RPC calls to create or execute a scheduled task via ATSvc
Detect an interactive AT job, which may be used as a form of privilege escalation.
Detects remote task creation via at.exe or API interacting with ATSVC namedpipe
Detects remote task creation via at.exe or API interacting with ATSVC namedpipe
Windows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE