An SOC analyst is reviewing MITRE ATT&CK guidance for scheduled-task persistence. A control recommendation states: 'Monitor task scheduler logs and alert on unusual task creation, modification, or deletion.' Which category does this guidance represent?
Select an answer to reveal the explanation.
Short Explanation
Think of a scheduled task like a recurring alarm you set for malware: blocking it before it starts is prevention, while spotting the alarm after it rings is detection. If the ATT&CK technique page tells you to hunt for task creation events, that’s detection coverage, not a preventive mitigation.
Full Explanation
MITRE ATT&CK separates mitigations, which reduce the likelihood or impact of an adversary behavior, from detection guidance, which supplies telemetry and analytics for identifying that behavior. For scheduled-task persistence, reviewing task scheduler logs and alerting on task creation, modification, or deletion is detection coverage because the control observes a persistence action instead of preventing the task from being created. Preventive mitigation for privilege escalation would address abuse of task creation rights, such as restricting who can schedule tasks or limiting token elevation, not log monitoring. Preventive mitigation for persistence would restrict scheduled-task creation or enforce application allowlisting, so the persistence action cannot occur. Detection coverage for command and control would rely on network beaconing, DNS patterns, TLS fingerprints, or process network connections, rather than task scheduler event logs. Exam caveat: a single ATT&CK technique can include both prevention and detection guidance, so classify the control by whether it stops the behavior or reveals it. Operational check: review a scheduled-task alert and confirm whether the supporting control is a prevention policy, such as task creation rights, or a detection analytic, such as event-log correlation.