Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.3 KiB

Detecting Malicious Scheduled Tasks with Sysmon — API Reference

Relevant Event IDs

Event ID Source Description
1 Sysmon Process Create — captures schtasks.exe with full command line
11 Sysmon File Create — task XML written to System32\Tasks
12/13 Sysmon Registry Create/Set — task registry modifications
4698 Security Scheduled task registered (includes task XML content)
4702 Security Scheduled task updated
4699 Security Scheduled task deleted

schtasks.exe Suspicious Flags

Flag Description Detection Value
/create Create new task Baseline detection
/s <host> Remote system target Lateral movement indicator
/ru SYSTEM Run as SYSTEM Privilege escalation
/sc onstart Run at system boot Persistence
/tr "powershell -enc" Encoded PowerShell payload Obfuscation
/tn \Microsoft\Windows\* Masquerade as Microsoft task Evasion

Splunk Detection Queries

index=sysmon EventCode=1 Image="*\\schtasks.exe" CommandLine="*/create*"
| eval suspicious=if(match(CommandLine,"(?i)(\\\\users\\\\public|\\\\temp\\\\|\\-enc)"),"YES","NO")
| where suspicious="YES"
index=wineventlog EventCode=4698
| spath input=TaskContent
| search Command="*powershell*" OR Command="*cmd.exe*"

Sysmon Configuration (Task Monitoring)

<RuleGroup groupRelation="or">
  <ProcessCreate onmatch="include">
    <Image condition="end with">schtasks.exe</Image>
    <Image condition="end with">at.exe</Image>
  </ProcessCreate>
  <FileCreate onmatch="include">
    <TargetFilename condition="contains">\Windows\System32\Tasks\</TargetFilename>
  </FileCreate>
</RuleGroup>

MITRE ATT&CK

Technique ID Description
Scheduled Task/Job T1053.005 Create/modify scheduled tasks for persistence
Lateral Movement T1021 Remote task creation via schtasks /s

External References