title: Defrag Deactivation id: c5a178bf-9cfb-4340-b584-e4df39b6a3e7 related: - id: 958d81aa-8566-4cea-a565-59ccd4df27b0 type: derived description: Detects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group status: experimental author: Florian Roth, Bartlomiej Czyz (@bczyz1) date: 2019/03/04 modified: 2021/09/19 references: - https://securelist.com/apt-slingshot/84312/ tags: - attack.persistence - attack.t1053 - attack.s0111 logsource: product: windows service: security definition: 'Requirements: Audit Policy : Audit Other Object Access Events > Success' detection: selection: EventID: 4701 TaskName: '\Microsoft\Windows\Defrag\ScheduledDefrag' condition: selection falsepositives: - Unknown level: medium