DragonForce Locker: COM Task Scheduler SYSTEM One-Time Task Registration
Detects DragonForce ransomware behavior where the binary is copied to a staging directory (typically C:\Users\Public\) and subsequently registered as a persistent, one-time execution scheduled task with SYSTEM privileges using COM interfaces or schtasks.exe.
Cortex XDR

