SHEETCREEP Malicious Scheduled Task Registration
Detects the creation of the WindowsVaultSyncService scheduled task or a task using the specific misleading description observed in SHEETCREEP (APT36) infections. The malware uses the Task Scheduler COM API to establish persistence.
Microsoft Sentinel (KQL)

