Detection of Renamed Schtasks Execution
Threat actors may rename the legitimate schtasks.exe Windows utility to evade security monitoring while establishing persistence or executing tasks.
Threat actors frequently leverage the legitimate Windows 'schtasks.exe' utility to establish persistence, execute malicious payloads, or achieve privilege escalation by scheduling tasks. Because this binary is heavily monitored by EDR and SIEM solutions, adversaries often employ evasion techniques, such as renaming the binary to a different filename to bypass basic file-path or process-name detection rules. Defenders must monitor for processes that exhibit command-line arguments consistent with schtasks.exe (such as '/create', '/delete', or '/run') while utilizing an image path that does not reflect the standard 'schtasks.exe' filename, or by checking the original file metadata when available in logs.
Impact
Successful abuse of scheduled tasks allows an attacker to maintain long-term persistence within a compromised environment, execute malicious code with system or user-level privileges, and automate post-exploitation tasks. If undetected, this can lead to broad system compromise and successful exfiltration or ransomware deployment.
Recommendation
Deploy the provided Sigma rule to monitor for suspicious process execution patterns that deviate from expected schtasks.exe behavior. Focus tuning on identifying non-standard filenames that invoke task-scheduling flags. Ensure that Sysmon or equivalent EDR telemetry includes both the image path and original file metadata (from the PE header) to detect renamed binaries reliably.
Immediate actions
Deploy Renamed Schtasks Execution Sigma rule to SIEM
Threat Hunt
Search for process execution where Image name is not schtasks.exe but CommandLine contains common task scheduling switches.
Data: Process creation logs with CommandLine and Image fields
Detection coverage 1
Detect Renamed Schtasks Execution
highDetects the execution of a renamed schtasks.exe binary by identifying common scheduling command-line arguments on non-standard binary names or mismatched original file metadata.
Detection queries are available on the platform. Get full rules →