Suspicious Task Scheduling via Schtasks
Detection of potentially malicious scheduled task creation or modification using specific trigger types that often bypass standard administrative activity monitoring.
This brief addresses the use of the schtasks.exe utility to create or modify tasks using specific, non-standard trigger types such as ONLOGON, ONSTART, ONCE, and ONIDLE. While these parameters are legitimate administrative functions within the Windows operating system, they are frequently abused by threat actors for persistence and lateral movement. Attackers leverage these schedule types to ensure malicious payloads execute automatically upon system startup, user logon, or during periods of inactivity. This activity has been observed in campaigns attributed to actors such as the Lazarus Group, who utilize scheduled tasks to maintain access and execute follow-on payloads. Defenders must distinguish between routine enterprise management activity and unauthorized task creation that lacks elevated (SYSTEM or HIGHEST) execution context.
Impact
Successful abuse of scheduled tasks allows attackers to maintain long-term persistence within a compromised environment. By triggering execution at system startup or user logon, attackers ensure their malicious tools survive reboots and user sessions. If left undetected, this enables attackers to deploy additional malware, exfiltrate sensitive data, or move laterally across the network, potentially impacting all systems where these tasks are established.
Recommendation
Deploy the provided Sigma rule to detect suspicious schtasks.exe invocations. Prioritize tuning for administrative software that legitimately configures tasks with these triggers to minimize false positives in the SOC.
- Enable Sysmon or Windows Security Event ID 4688 (Process Creation) logging.
- Implement the detection logic in your SIEM and tune against known-good management scripts.
- Audit existing tasks on high-value assets for entries created with the suspicious trigger types listed.
Immediate actions
Deploy the Sigma rule to the SIEM and run in monitor-only mode for 7 days to baseline volume.
Threat Hunt
Search for existing tasks created with /sc ONLOGON or /sc ONSTART that do not have an associated SYSTEM or HIGHEST execution context.
Data: Scheduled Task logs or Schtasks output
Mitigations
Restrict the ability of non-administrative users to create or modify scheduled tasks via Group Policy.
Detection coverage 1
Detect Suspicious Schtasks Schedule Types
highDetects scheduled task creation or modification using specific trigger types (ONLOGON, ONSTART, ONCE, ONIDLE) that do not specify high-privilege execution, which is often indicative of malicious persistence attempts.
Detection queries are available on the platform. Get full rules →