Ransomware Series: Scheduled Task Creation for Persistence or Payload Execution
Detects the creation of scheduled tasks using schtasks.exe or PowerShell cmdlets that execute with SYSTEM privileges, or tasks that reference common temporary directories or persistence triggers (logon, idle). This behavior is frequently associated with ransomware, malware persistence, or staged payload execution.
Microsoft Sentinel (KQL)

