Rule library
// Detection
Persistence mechanism created
A scheduled task, service or run key established on a host, giving an intruder a way back after reboot.
HighInvestigating0alerts raisedSignature
Armed
What this rule does
Rendered from the stored logic, so it cannot drift from what executes.
Any event where eventType is PERSISTENCE_CREATED
{
"kind": "match",
"where": [
{
"op": "eq",
"field": "eventType",
"value": "PERSISTENCE_CREATED"
}
]
}Revise
Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.
Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city
Alerts raised (0)
What this rule has actually caught.
Never fired
Armed, but nothing in the retained window has matched it.
Rule
- Category
- Persistence
- ATT&CK tactic
- Persistence
- Technique
- T1053.005
- Kind
- Signature
- State
- Armed
- Created
- 7d ago
- Last changed
- 7d ago
Firing history
- Total alerts
- 0
- First fired
- Never
- Last fired
- Never
- Escalated to cases
- 0
- Dismissed benign
- 0