COM-Based Scheduled Task Registration with SYSTEM Principal (One-Time Trigger)

Detects the creation of a Windows scheduled task configured to execute as the SYSTEM account using a one-time execution trigger. This combination is frequently used by adversaries for post-exploitation activities, such as lateral movement or persistence, as it allows for a single, immediate execution of a malicious payload with high-level privileges.