title: New TaskCache Entry author: Syed Hasan (@syedhasan009) date: 2021/06/18 description: Monitor the creation of a new key under 'TaskCache' when a new scheduled task is registered detection: SELECTION_1: EventID: 12 SELECTION_2: EventID: 13 SELECTION_3: EventID: 14 SELECTION_4: EventType: SetValue SELECTION_5: TargetObject: '*SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\\*' condition: ((SELECTION_1 or SELECTION_2 or SELECTION_3) and SELECTION_4 and SELECTION_5) falsepositives: - Unknown id: 4720b7df-40c3-48fd-bbdf-fd4b3c464f0d level: medium logsource: category: registry_event product: windows modified: 2021/07/27 references: - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ tags: - attack.persistence - attack.t1053 - attack.t1053.005 yml_filename: sysmon_taskcache_entry.yml yml_path: /Users/user/Documents/YamatoSecurity/sigma/rules/windows/registry_event