Run the RTA with the fix to check it executes with no errors
(venv) PS C:\Users\shashank_suryanaraya\detection-rules> python -m rta -n schtask_escalation
[+] Scheduled Task Privilege Escalation
shashank_suryanaraya @ e2e-release-windows-server-2022 > schtasks.exe /query /tn test-task-rta
ERROR: The system cannot find the file specified.
exit code = 1
shashank_suryanaraya @ e2e-release-windows-server-2022 > schtasks.exe /create /tn test-task-rta /ru system /tr "cmd.exe /c whoami.exe > task.log" /sc onlogon
SUCCESS: The scheduled task "test-task-rta" has successfully been created.
shashank_suryanaraya @ e2e-release-windows-server-2022 > schtasks.exe /run /tn test-task-rta
SUCCESS: Attempted to run the scheduled task "test-task-rta".
task.log
--- NOT FOUND ----
shashank_suryanaraya @ e2e-release-windows-server-2022 > schtasks.exe /delete /tn test-task-rta /f
SUCCESS: The scheduled task "test-task-rta" was successfully deleted.
(venv) PS C:\Users\shashank_suryanaraya\detection-rules>
Checklist
[x] Added a label for the type of pr: bug, enhancement, schema, Rule: New, Rule: Deprecation, Rule: Tuning, Hunt: New, or Hunt: Tuning so guidelines can be generated
[x] Added the meta:rapid-merge label if planning to merge within 24 hours
[ ] Secret and sensitive material has been managed correctly
[ ] Automated testing was updated or added to match the most common scenarios
[ ] Documentation and comments were added for features that require explanation
Pull Request
Issue link(s): Reported in Community Slack
Summary - What I changed
How To Test
Checklist
bug
,enhancement
,schema
,Rule: New
,Rule: Deprecation
,Rule: Tuning
,Hunt: New
, orHunt: Tuning
so guidelines can be generatedmeta:rapid-merge
label if planning to merge within 24 hoursContributor checklist