A SOC analyst investigates suspicious activity from a service account and suspects scheduled-task persistence. Which hunting query best maps to ATT&CK T1053.005?
Select an answer to reveal the explanation.
Short Explanation
Think of scheduled-task persistence as a sneaky alarm clock: it doesn't need a login, it just wakes up on a timer. You want the Event ID 4698 task-creation breadcrumbs and the schtasks.exe /create process that set them, not noisy logon or beaconing noise. That pairing is the tightest map to ATT&CK T1053.005.
Full Explanation
The mechanism here is that ATT&CK T1053.005 describes adversary persistence by registering a scheduled task so code executes at a defined time, boot, or logon. In Windows telemetry, the highest-confidence hunting signal pairs Event ID 4698, which records a scheduled task being created, with process-creation evidence of schtasks.exe invoked with /create or equivalent task-registration arguments. This correlation is strong because it links the durable artifact to the process that created it, reducing false positives from benign administrative scheduling. Logon-event hunting focuses on authentication abuse and credential guessing, not the creation of a persistence mechanism. DNS-tunneling and beaconing analysis targets command-and-control channel behavior, which may follow persistence but does not identify task registration. SMB or firewall hunting for external file-share or exploit traffic is relevant to lateral movement or exploitation, not scheduled-task persistence. Exam caveat: the question asks for the query that implements the ATT&CK technique, so choose the telemetry that proves the persistence action itself rather than a related IOC. Operational check: query the SIEM for Event ID 4698 joined to EDR process events for schtasks.exe /create, then inspect task XML, command line, author, and schedule.