Rules Contributing to Persistence and Execution at Scale via GPO Scheduled Task Alert

The following rules detect suspicious SMB traffic related to GPO scheduled task creation/access. Any one or more of these will trigger the Persistence and Execution at Scale via GPO Scheduled Task Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Persistence and Execution at Scale via GPO Scheduled Task

Detect lateral movement using GPO scheduled task, usually used to deploy ransomware at scale