Suspicious Scheduled Task Creation by Scripting Engine (Persistence)
Detects the creation of scheduled tasks (schtasks.exe) spawned by common scripting or social engineering-related parent processes (PowerShell, Cmd, WScript, MSHTA). The rule specifically looks for payloads associated with common attack patterns, such as downloading remote content or executing encoded commands, which indicates potential persistence or payload delivery activities.
SentinelOne

