Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor - Task Scheduler
Hunts for known SVR-specific scheduled task names
Detection logic
selection
EventID:
- 129
- 140
- 141
TaskName:
- \defender
- \Microsoft\DefenderService
- \Microsoft\Windows\Application Experience\StartupAppTaskCheck
- \Microsoft\Windows\Application Experience\StartupAppTaskCkeck
- \Microsoft\Windows\ATPUpd
- \Microsoft\Windows\Data Integrity Scan\Data Integrity Update
- \Microsoft\Windows\DefenderUPDService
- \Microsoft\Windows\IISUpdateService
- \Microsoft\Windows\Speech\SpeechModelInstallTask
- \Microsoft\Windows\WiMSDFS
- \Microsoft\Windows\Windows Defender\Defender Update Service
- \Microsoft\Windows\Windows Defender\Service Update
- \Microsoft\Windows\Windows Error Reporting\CheckReporting
- \Microsoft\Windows\Windows Error Reporting\SubmitReporting
- \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStart
- \Microsoft\Windows\WindowsDefenderService
- \Microsoft\Windows\WindowsDefenderService2
- \Microsoft\Windows\WindowsUpdate\Scheduled AutoCheck
- \Microsoft\Windows\WindowsUpdate\Scheduled Check
- \WindowUpdateCondition
selectionRaw YAML
title: Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor - Task Scheduler
id: 2bfc1373-0220-4fbd-8b10-33ddafd2a142
related:
- id: 8fa65166-f463-4fd2-ad4f-1436133c52e1 # Security-Audting Eventlog
type: similar
status: test
description: Hunts for known SVR-specific scheduled task names
author: CISA
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
date: 2023-12-18
tags:
- attack.persistence
- detection.emerging-threats
logsource:
product: windows
service: taskscheduler
definition: 'Requirements: The "Microsoft-Windows-TaskScheduler/Operational" is disabled by default and needs to be enabled in order for this detection to trigger'
detection:
selection:
EventID:
- 129 # Task Created
- 140 # Task Updated
- 141 # Task Deleted
TaskName:
- '\defender'
- '\Microsoft\DefenderService'
- '\Microsoft\Windows\Application Experience\StartupAppTaskCheck'
- '\Microsoft\Windows\Application Experience\StartupAppTaskCkeck'
- '\Microsoft\Windows\ATPUpd'
- '\Microsoft\Windows\Data Integrity Scan\Data Integrity Update'
- '\Microsoft\Windows\DefenderUPDService'
- '\Microsoft\Windows\IISUpdateService'
- '\Microsoft\Windows\Speech\SpeechModelInstallTask'
- '\Microsoft\Windows\WiMSDFS'
- '\Microsoft\Windows\Windows Defender\Defender Update Service'
- '\Microsoft\Windows\Windows Defender\Service Update'
- '\Microsoft\Windows\Windows Error Reporting\CheckReporting'
- '\Microsoft\Windows\Windows Error Reporting\SubmitReporting'
- '\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStart'
- '\Microsoft\Windows\WindowsDefenderService'
- '\Microsoft\Windows\WindowsDefenderService2'
- '\Microsoft\Windows\WindowsUpdate\Scheduled AutoCheck'
- '\Microsoft\Windows\WindowsUpdate\Scheduled Check'
- '\WindowUpdate'
condition: selection
falsepositives:
- Unknown
level: highFalse positives
- Unknown