BeepRAT Scheduled Task Persistence via schtasks in User Writable Paths
Detects the creation of Windows scheduled tasks using 'schtasks.exe' where the executable being registered or the task itself is associated with suspicious directories like %LOCALAPPDATA%, %APPDATA%, or %TEMP%. The rule further filters for specific suspicious strings often used in malicious task configurations, indicating potential persistence or malicious command execution.
Cortex XDR

