Scheduled Task Persistence via schtasks.exe with Suspicious Payload

Detects the creation of Windows scheduled tasks that include suspicious interpreters (PowerShell, cmd.exe, rundll32) or execution paths located in common attacker-writable directories (Temp, AppData, ProgramData), which is a common technique for persistence and command-and-control re-establishment.