Suspicious Scheduled Task Creation with Scripting Languages
This rule detects the creation or modification of scheduled tasks (EventID 4698 or 4699) where the command line for the task contains references to scripting languages like PowerShell, cmd, or VBScript. It then groups these events by computer and user, flagging if two or more such tasks are created by the same user on the same computer, which could indicate malicious activity.
Microsoft Sentinel (KQL)

