{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/scheduled-tasks/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["medium"],"_cs_tags":["persistence","scheduled-tasks","windows","detection-engineering"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThis brief addresses the use of Windows Scheduled Tasks by threat actors to establish persistence, elevate privileges, or facilitate the execution of malicious code. Attackers frequently register tasks with specific naming patterns to mask their activity or follow naming conventions identified in previous campaigns. Defenders can identify this activity by monitoring Windows Security Event logs for task creation (4698), modification (4702), and enablement (4700). Security teams should monitor for these events and compare registered task names against internal watchlists or intelligence-derived lists of known suspicious task names. This analytic is particularly relevant for identifying techniques employed by diverse threat groups, including those associated with ransomware families like Ryuk and various information stealers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of scheduled tasks enables threat actors to maintain long-term unauthorized access to a system, execute arbitrary payloads with elevated permissions, or bypass basic security controls. This activity is a common precursor to wider network compromise, data exfiltration, or ransomware deployment. Organizations may face significant operational disruption and data loss if persistent malicious tasks remain undetected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Windows Security Event Log auditing for Task Scheduler events (Event IDs 4698, 4700, 4702) across all endpoints.\u003c/li\u003e\n\u003cli\u003eImplement a centralized watchlist of suspicious task names derived from threat intelligence to flag anomalous registrations.\u003c/li\u003e\n\u003cli\u003eInvestigate any scheduled task creation that includes shell commands or binary execution paths from suspicious directories (e.g., Temp, AppData).\u003c/li\u003e\n\u003cli\u003eUse the provided drilldown searches to correlate alerts with user identity and system context to distinguish between administrative tasks and malicious activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T12:27:59Z","date_published":"2026-10-05T12:27:59Z","id":"https://feed.craftedsignal.io/briefs/2026-10-suspicious-scheduled-tasks/","summary":"Detection logic targeting the creation, modification, or enabling of Windows Scheduled Tasks that utilize known malicious or suspicious naming conventions often associated with persistence and payload execution.","title":"Detection of Malicious Windows Scheduled Task Names","url":"https://feed.craftedsignal.io/briefs/2026-10-suspicious-scheduled-tasks/"}],"language":"en","title":"CraftedSignal Threat Feed - Scheduled-Tasks","version":"https://jsonfeed.org/version/1.1"}