1200KM / detection
T1053.005 Scheduled Task — Detection Rules
Detection workspace for T1053.005 Scheduled Task: 31 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Persistence and Execution at Scale via GPO Scheduled Task · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- Suspicious Scheduled Task Creation · test · high · {"product":"windows","service":"security","definition":"The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data."}
- Important Scheduled Task Deleted/Disabled · test · high · {"product":"windows","service":"security","definition":"The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data."}
- Suspicious Scheduled Task Update · test · high · {"product":"windows","service":"security","definition":"The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to allow this detection. We also recommend extracting the Command field from the embedded XML in the event data."}
- Scheduled Task Executed From A Suspicious Location · test · medium · {"product":"windows","service":"taskscheduler","definition":"Requirements: The \"Microsoft-Windows-TaskScheduler/Operational\" is disabled by default and needs to be enabled in order for this detection to trigger"}
- Scheduled Task Executed Uncommon LOLBIN · test · medium · {"product":"windows","service":"taskscheduler","definition":"Requirements: The \"Microsoft-Windows-TaskScheduler/Operational\" is disabled by default and needs to be enabled in order for this detection to trigger"}
- Powershell Create Scheduled Task · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - Default PowerSploit/Empire Scheduled Task Creation · test · high · {"product":"windows","category":"process_creation"}
- Renamed Schtasks Execution · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious Schtasks Execution AppData Folder · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Modification Of Scheduled Tasks · test · high · {"product":"windows","category":"process_creation"}
- Scheduled Task Creation Via Schtasks.EXE · test · low · {"category":"process_creation","product":"windows"}
- Suspicious Scheduled Task Creation Involving Temp Folder · test · high · {"category":"process_creation","product":"windows"}
- Scheduled Task Creation with Curl and PowerShell Execution Combo · experimental · medium · {"category":"process_creation","product":"windows"}
- Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Schtasks From Suspicious Folders · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Scheduled Task Name As GUID · test · medium · {"product":"windows","category":"process_creation"}
- Uncommon One Time Only Scheduled Task At 00:00 · test · high · {"category":"process_creation","product":"windows"}
- Potential SSH Tunnel Persistence Install Using A Scheduled Task · experimental · high · {"product":"windows","category":"process_creation"}
- Potential Persistence Via Microsoft Compatibility Appraiser · test · medium · {"product":"windows","category":"process_creation"}
- Potential Persistence Via Powershell Search Order Hijacking - Task · test · high · {"product":"windows","category":"process_creation"}
- Scheduled Task Executing Payload from Registry · test · medium · {"product":"windows","category":"process_creation"}
- Scheduled Task Executing Encoded Payload from Registry · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Schtasks Schedule Types · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Schtasks Schedule Type With High Privileges · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious Scheduled Task Creation via Masqueraded XML File · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious Command Patterns In Scheduled Task Creation · test · high · {"product":"windows","category":"process_creation"}
- Schtasks Creation Or Modification With SYSTEM Privileges · test · high · {"product":"windows","category":"process_creation"}
- Scheduled Task Creation Masquerading as System Processes · experimental · high · {"category":"process_creation","product":"windows"}
- Scheduled TaskCache Change by Uncommon Program · test · high · {"category":"registry_set","product":"windows"}
- Potential Registry Persistence Attempt Via Windows Telemetry · test · high · {"category":"registry_set","product":"windows","definition":"Requirements: Sysmon config that monitors \\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\TelemetryController subkey of the HKLM hives"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0441 Detection of Suspicious Scheduled Task Creation and Execution on Windows
AN1221 Analytic 1221
Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT29 · G0016
- Naikon · G0019
- Molerats · G0021
- APT3 · G0022
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Stealth Falcon · G0038
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- APT37 · G0067
- MuddyWater · G0069
- Rancor · G0075
- Cobalt Group · G0080
- APT38 · G0082
- APT39 · G0087
- Silence · G0091
- GALLIUM · G0093
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- APT-C-36 · G0099
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Higaisa · G0126
- Mustang Panda · G0129
- Confucius · G0142
- HEXANE · G1001
- BITTER · G1002
- Ember Bear · G1003
- Earth Lusca · G1006
- LuminousMoth · G1014
- FIN13 · G1016
- TA2541 · G1018
- ToddyCat · G1022
- Daggerfly · G1034
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- RedCurl · G1039
- BlackByte · G1043
- APT42 · G1044
- Storm-0501 · G1053
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.