SynkLoader Scheduled Task Created via COM Interface for Persistence
Detects the creation of a scheduled task via the Windows COM interface, a technique used by malware like SynkLoader to bypass command-line monitoring (e.g., schtasks.exe). The rule monitors Windows Security Event IDs 4698 and 4702 for tasks configured to trigger on logon that execute script-based content (Python or PowerShell) from user-writable directories.
Cortex XDR

