Schtasks Used For Forcing A Reboot
This search looks for flags passed to schtasks.exe on the command-line that indicate that a forced reboot of system is scheduled.
Schtasks Used For Forcing A Reboot Help
To successfully implement this search you need to be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
Open in Search