Ransomware Series: SocGholish/Ransomware Scheduled Task Persistence via schtasks
Detects the creation of scheduled tasks using schtasks.exe initiated by command shells where the task command points to files residing in non-standard or user-writable directories such as \Users\Public\, \PerfLogs\, or \ProgramData\. This pattern is frequently utilized by malware loaders like SocGholish, GootLoader, and various ransomware strains to achieve persistence following initial compromise.
Sigma

