As cited
Copy frozen at (site build).
threat intel
Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)
This technical guide demonstrates how to hunt for two Windows persistence techniques: Scheduled Tasks (T1053) and BITS Jobs (T1197). The article explains the command line parameters, PowerShell cmdlets, and real-world examples of how threat groups like APT34 and malware families like Qbot abuse these built-in utilities, then provides Event Query Language (EQL) detection queries for security teams to identify malicious activity in their environments.
Why it matters: Security practitioners need to understand and detect persistence mechanisms that threat actors commonly abuse, as identifying scheduled tasks and BITS jobs created by suspicious processes can reveal ongoing compromise and prevent data exfiltration or remote code execution in Windows environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)
This technical guide demonstrates how to hunt for two Windows persistence techniques: Scheduled Tasks (T1053) and BITS Jobs (T1197). The article explains the command line parameters, PowerShell cmdlets, and real-world examples of how threat groups like APT34 and malware families like Qbot abuse these built-in utilities, then provides Event Query Language (EQL) detection queries for security teams to identify malicious activity in their environments.
Why it matters: Security practitioners need to understand and detect persistence mechanisms that threat actors commonly abuse, as identifying scheduled tasks and BITS jobs created by suspicious processes can reveal ongoing compromise and prevent data exfiltration or remote code execution in Windows environments.
- Source published
- First seen by Cybersecurity Tracker