Star Blizzard masquerading scheduled tasks with WebDAV C2 retrieval

This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.