UNK_DoubleCheck persistence via scheduled tasks and CLSID hijack
This rule monitors for potential persistence and malicious activity by aggregating three distinct detection signals: COM hijacking attempts via the InprocServer32 registry key, the creation of scheduled tasks using specific suspicious naming conventions, and the identification of named mutexes indicative of specific malware presence.
Microsoft Sentinel (KQL)

