We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Behavior:Win32/SevSchtaskCreateByFriendly.gen!A
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
This is a behavior-based detection for processes that schedule suspicious tasks.
To mitigate the threat, follow these steps:
- Apply security updates promptly on all applications and operating systems. Consult the Microsoft Security Update Guide for comprehensive information on available Microsoft Security updates.
- Follow the principle of least privilege and maintain credential hygiene. Avoid using domain-wide, admin-level service accounts. Restrict local administrative privileges to mitigate the installation of remote access trojans (RATs) and other undesirable applications.
- Encourage the use of Microsoft Edge and other web browsers that support SmartScreen, which identifies and blocks malicious websites. Turn on network protection to block connections to malicious domains and IP addresses.