- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Detects when critical Windows system scheduled tasks are deleted or disabled.
This detection monitors event logs for deletion (Event ID 4699) or disabling (Event ID 4701) of critical scheduled tasks related to system security and maintenance. For deletion events, it specifically filters out service account activity by excluding events where SubjectUserName
ends with “$”. The detection looks for tasks matching specific patterns such as paths containing Windows Defender, BitLocker, System Restore, Windows Update, and other security-related scheduled tasks.
These critical scheduled tasks are essential components of Windows security infrastructure, providing functions like automated backups, malware scanning, and system updates. Tampering with these tasks could indicate defense evasion tactics being employed by threat actors attempting to weaken security controls.
{{host}}
where the critical scheduled task was deleted or disabled.