1200KM / simulation
T1053.005 Scheduled Task — Attack Simulation
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task…
Technique description
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Scheduled Task Persistence via Eventviewer.msc
Procedure 02124c37-767e-4b76-9383-c9fc366d9d4c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Turla Topinambour Dropper and Scheduled Task Persistence
Procedure 1a73e89e-a5de-404d-9784-5c2aa0b38a29; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Scheduled task Remote
Procedure 2e5eac3e-327b-4a88-a0c0-c4057039a8dd; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Scheduled task Local
Procedure 42f53695-ad4a-4546-abb6-7d837f644a71; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Turla KopiLuwak Scheduled Task for JavaScript Stager
Procedure 6731e8a0-5aeb-4180-8a90-4f8852e56de6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Scheduled Task ("Ghost Task") via Registry Key Manipulation
Procedure 704333ca-cc12-4bcf-9916-101844881f54; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Scheduled Task Persistence via CompMgmt.msc
Procedure 8fcfa3d5-ea7d-4e1c-bd3e-3c4ed315b7d2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Powershell Cmdlet Scheduled Task
Procedure af9fd58f-c4ac-4bf2-a9ba-224b71ff25fd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Import XML Schedule Task with Hidden Attribute
Procedure cd925593-fbb4-486d-8def-16cbdf944bf4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- PowerShell Modify A Scheduled Task
Procedure dda6fc7b-c9a6-4c18-b98d-95ec6542af6d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WMI Invoke-CimMethod Scheduled Task
Procedure e16b3b75-dc9e-4cde-a23d-dfa2d0507b3b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Scheduled Task Executing Base64 Encoded Commands From Registry
Procedure e895677d-4f06-49ab-91b6-ae3742d0a2ba; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Task Scheduler via VBA
Procedure ecd3fa21-7792-41a2-8726-2c5c673414d3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Scheduled Task Startup Script
Procedure fec27f65-db86-4c2d-b66c-61945aee87c2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT29 · G0016
- Naikon · G0019
- Molerats · G0021
- APT3 · G0022
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Stealth Falcon · G0038
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- APT37 · G0067
- MuddyWater · G0069
- Rancor · G0075
- Cobalt Group · G0080
- APT38 · G0082
- APT39 · G0087
- Silence · G0091
- GALLIUM · G0093
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- APT-C-36 · G0099
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Higaisa · G0126
- Mustang Panda · G0129
- Confucius · G0142
- HEXANE · G1001
- BITTER · G1002
- Ember Bear · G1003
- Earth Lusca · G1006
- LuminousMoth · G1014
- FIN13 · G1016
- TA2541 · G1018
- ToddyCat · G1022
- Daggerfly · G1034
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- RedCurl · G1039
- BlackByte · G1043
- APT42 · G1044
- Storm-0501 · G1053
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.