Rule library
// Detection

Persistence mechanism created

A scheduled task, service or run key established on a host, giving an intruder a way back after reboot.

HighInvestigating0alerts raisedSignature
Armed

What this rule does

Rendered from the stored logic, so it cannot drift from what executes.

Any event where eventType is PERSISTENCE_CREATED

{
  "kind": "match",
  "where": [
    {
      "op": "eq",
      "field": "eventType",
      "value": "PERSISTENCE_CREATED"
    }
  ]
}

Revise

Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.

Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city

Alerts raised (0)

What this rule has actually caught.

Never fired

Armed, but nothing in the retained window has matched it.

Rule

Category
Persistence
ATT&CK tactic
Persistence
Technique
T1053.005
Kind
Signature
State
Armed
Created
7d ago
Last changed
7d ago

Firing history

Total alerts
0
First fired
Never
Last fired
Never
Escalated to cases
0
Dismissed benign
0

Related