KuinaExtractor UAC Bypass via SilentCleanup Scheduled Task (T1548.002)
Detects the KuinaExtractor UAC bypass technique, which exploits the auto-elevated 'SilentCleanup' scheduled task. The rule identifies suspicious activity via two patterns: the execution of 'cleanmgr.exe' from an unexpected parent process (bypassing normal task scheduler invocation) or the explicit execution of 'schtasks.exe' to trigger the 'SilentCleanup' task.
Microsoft Sentinel (KQL)

