CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5196

As cited

Copy frozen at (site build).

threat intel

Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)

This technical guide demonstrates how to hunt for two Windows persistence techniques: Scheduled Tasks (T1053) and BITS Jobs (T1197). The article explains the command line parameters, PowerShell cmdlets, and real-world examples of how threat groups like APT34 and malware families like Qbot abuse these built-in utilities, then provides Event Query Language (EQL) detection queries for security teams to identify malicious activity in their environments.

Why it matters: Security practitioners need to understand and detect persistence mechanisms that threat actors commonly abuse, as identifying scheduled tasks and BITS jobs created by suspicious processes can reveal ongoing compromise and prevent data exfiltration or remote code execution in Windows environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)

This technical guide demonstrates how to hunt for two Windows persistence techniques: Scheduled Tasks (T1053) and BITS Jobs (T1197). The article explains the command line parameters, PowerShell cmdlets, and real-world examples of how threat groups like APT34 and malware families like Qbot abuse these built-in utilities, then provides Event Query Language (EQL) detection queries for security teams to identify malicious activity in their environments.

Why it matters: Security practitioners need to understand and detect persistence mechanisms that threat actors commonly abuse, as identifying scheduled tasks and BITS jobs created by suspicious processes can reveal ongoing compromise and prevent data exfiltration or remote code execution in Windows environments.

VendorsMicrosoftElastic
Actorsapt29
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary