Scheduled Task Creation with Script Execution
This rule detects the creation or modification of scheduled tasks using utilities like schtasks.exe or at.exe that are followed by the execution of script-based interpreters (PowerShell, CMD, or WScript). This pattern is commonly indicative of an attacker establishing persistence by scheduling malicious scripts to run automatically.
Microsoft Sentinel (KQL)

