A Sigma rule fires when schtasks /create is used to add a task that launches a script at system startup. In MITRE ATT&CK, which persistence technique does this detection most directly map to?
Select an answer to reveal the explanation.
Short Explanation
Think of schtasks as a calendar entry: it doesn’t matter who wrote the calendar, it matters that something now runs when the machine wakes up. If your Sigma rule sees a scheduled task being created, you’re looking at persistence through the task scheduler, not a service or login script. Don’t chase the command name—map the behavior the attacker wants to keep running.
Full Explanation
The mapping follows the behavior the Sigma rule captures, not the name of the command. A rule that alerts on schtasks /create is observing creation of a Windows Task Scheduler job, which adversaries use to establish persistence by running a payload at startup, logon, or a recurring interval. In MITRE ATT&CK, that behavior is classified under Scheduled Task/Job, commonly the Scheduled Task subtechnique. It is not Boot or Logon Autostart Execution because that family covers startup locations and registry autostart entries such as Run keys, startup folders, or shell extensions. It is not Logon Script Initialization because that covers scripts executed during login through environment variables, profile scripts, or login scripts. It is not Service Execution because services are managed through service control mechanisms and service binaries, not task scheduler entries. Exam caveat: map detections to the adversary action observed, not the utility name alone. Operational check: confirm the alert by retrieving the task definition, trigger, and action to verify startup, logon, or recurring persistence.