Skip to content
Threat Feed
high advisory

Detection of Renamed Schtasks Execution

Threat actors may rename the legitimate schtasks.exe Windows utility to evade security monitoring while establishing persistence or executing tasks.

Threat actors frequently leverage the legitimate Windows 'schtasks.exe' utility to establish persistence, execute malicious payloads, or achieve privilege escalation by scheduling tasks. Because this binary is heavily monitored by EDR and SIEM solutions, adversaries often employ evasion techniques, such as renaming the binary to a different filename to bypass basic file-path or process-name detection rules. Defenders must monitor for processes that exhibit command-line arguments consistent with schtasks.exe (such as '/create', '/delete', or '/run') while utilizing an image path that does not reflect the standard 'schtasks.exe' filename, or by checking the original file metadata when available in logs.

Impact

Successful abuse of scheduled tasks allows an attacker to maintain long-term persistence within a compromised environment, execute malicious code with system or user-level privileges, and automate post-exploitation tasks. If undetected, this can lead to broad system compromise and successful exfiltration or ransomware deployment.

Recommendation

Deploy the provided Sigma rule to monitor for suspicious process execution patterns that deviate from expected schtasks.exe behavior. Focus tuning on identifying non-standard filenames that invoke task-scheduling flags. Ensure that Sysmon or equivalent EDR telemetry includes both the image path and original file metadata (from the PE header) to detect renamed binaries reliably.


Immediate actions

Deploy Renamed Schtasks Execution Sigma rule to SIEM

Detection Engineering 72h

Threat Hunt

Search for process execution where Image name is not schtasks.exe but CommandLine contains common task scheduling switches.

T1036.003 medium high confidence hunt now

Data: Process creation logs with CommandLine and Image fields

Detection coverage 1

Detect Renamed Schtasks Execution

high

Detects the execution of a renamed schtasks.exe binary by identifying common scheduling command-line arguments on non-standard binary names or mismatched original file metadata.

sigma tactics: execution, persistence, privilege-escalation, stealth techniques: T1036.003, T1053.005 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →