⌕
Showing 12 of 12 events
Cross-channel reference for Windows Scheduled Task forensic analysis. Covers Security.evtx audit events (require advanced audit policy) and the always-on TaskScheduler/Operational log. Focused on persistence, task hijacking, and lateral movement via the Task Scheduler.
Curated highest-signal Sigma-style detection rules for Scheduled Task Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.
Convert to your SIEM: sigconverter.io