Suspicious schtasks.exe Creation — External URL, Encoded Cmd, or User-Writable Path with SYSTEM/Logon Trigger

Detects the creation of scheduled tasks using schtasks.exe that exhibit suspicious characteristics. This includes tasks referencing external URLs, those containing base64-encoded or obfuscated command strings, and tasks pointing to binaries or scripts in user-writable paths (e.g., AppData, Temp). The rule specifically targets tasks intended to run with SYSTEM privileges or those using common persistence triggers, while excluding known legitimate administrative software.