Analytics BIOC
Informational
✕
Uncommon local scheduled task creation via schtasks.exe
The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Scheduled Task/Job (T1053)
Detector tags: Scheduled tasks Analytics
Attacker's goals:
Attackers may attempt to use the command to gain persistence on the endpoint using scheduled tasks.
Investigative actions:
Review the process that creates the schedule task. Investigate the specific scheduled task execution chain.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Uncommon local scheduled task creation via schtasks.exe by a remote actor Informational
- Uncommon scheduled task created by an unsigned and rare actor via schtasks.exe Low (parent: Informational)
- Uncommon scheduled task created by an unsigned actor via schtasks.exe Low (parent: Informational)
- Uncommon scheduled task created by a signed actor from a rare vendor via schtasks.exe Low (parent: Informational)