Built off the open source project Osquery
Description: Bad Rabbit Scheduled Tasks
What The Data Shows: Provides IOC for BadRabbit
SQL:
SELECT name,action,path,enabled,state,hidden,
datetime(last_run_time,"unixepoch","localtime") AS last_run_time,
datetime(next_run_time,"unixepoch","localtime") AS next_run_time,
last_run_message,last_run_code
FROM (`scheduled_tasks` )
WHERE (`name` = 'drogon') or (`name` = 'Rhaegel');
Copyright © 2005-2023 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.