Scheduled task created via CLSID_TaskScheduler COM interface instead of schtasks.exe
This rule detects the creation of a scheduled task where the initiating process is not the standard 'schtasks.exe'. It monitors for activity associated with COM objects (CLSID_TaskScheduler, ITaskService) typically used by applications to interact with the Task Scheduler API programmatically, which is a common technique for persistence or execution in non-standard ways.
Microsoft Sentinel (KQL)

