Obfuscated Scheduled Task Leveraging PowerShell XOR Loader
Detects scheduled tasks created with embedded PowerShell XOR decoding logic, ReadAllBytes, and Invoke-Expression techniques that may be used to establish persistence and execute obfuscated payloads. The rule specifically looks for 'schtasks.exe' creating a task with '/create', containing 'OneDrive', 'Startup', 'Task' in the command line, and also includes '-bxor', 'ReadAllBytes', 'iex', and '[Text.Encoding]::UTF8.GetBytes' which are indicative of obfuscated PowerShell execution via XOR decoding.
Microsoft Sentinel (KQL)

