Skip to content
Threat Feed
high advisory

Detection of Important Scheduled Task Deletion or Disablement

Adversaries delete or disable critical scheduled tasks, such as those related to system restore, Windows Defender, BitLocker, Windows Backup, or Windows Update, to disrupt operations and potentially conduct data destructive activities.

This brief focuses on the detection of malicious activity related to the deletion or disabling of important scheduled tasks within a Windows environment. Adversaries may target these tasks to disrupt normal system operations, escalate privileges, establish persistence, or facilitate data destruction. The targeted tasks often include critical system functions like System Restore, Windows Defender updates, BitLocker encryption, Windows Backup processes, and Windows Update mechanisms. This…

Detection coverage 2

Suspicious Scheduled Task Deletion/Disablement of Critical Tasks

high

Detects the deletion or disabling of important scheduled tasks based on Event ID and Task Name.

sigma tactics: execution, persistence, privilege-escalation techniques: T1053.005 sources: windows, security

Scheduled Task Deletion via Schtasks.exe

medium

Detects the execution of schtasks.exe to delete scheduled tasks, which may indicate malicious activity.

sigma tactics: execution techniques: T1053.005 sources: process_creation, windows

Detection queries are kept inside the platform. Get full rules →