Sauron Loader 'keyroll' Scheduled Task Persistence
This rule detects the creation of Windows Scheduled Tasks by monitoring for Event ID 4698 (Windows Security Log) or Sysmon Event ID 1 (Process Creation) that involves task name parameters. Adversaries frequently use the Windows Task Scheduler to establish persistence, execute malicious code, or run tasks at system startup.
Splunk (SPL)

