<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Scheduled-Tasks - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/scheduled-tasks/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:27:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/scheduled-tasks/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Malicious Windows Scheduled Task Names</title><link>https://feed.craftedsignal.io/briefs/2026-10-suspicious-scheduled-tasks/</link><pubDate>Mon, 05 Oct 2026 12:27:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-suspicious-scheduled-tasks/</guid><description>Detection logic targeting the creation, modification, or enabling of Windows Scheduled Tasks that utilize known malicious or suspicious naming conventions often associated with persistence and payload execution.</description><content:encoded><![CDATA[<p>This brief addresses the use of Windows Scheduled Tasks by threat actors to establish persistence, elevate privileges, or facilitate the execution of malicious code. Attackers frequently register tasks with specific naming patterns to mask their activity or follow naming conventions identified in previous campaigns. Defenders can identify this activity by monitoring Windows Security Event logs for task creation (4698), modification (4702), and enablement (4700). Security teams should monitor for these events and compare registered task names against internal watchlists or intelligence-derived lists of known suspicious task names. This analytic is particularly relevant for identifying techniques employed by diverse threat groups, including those associated with ransomware families like Ryuk and various information stealers.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of scheduled tasks enables threat actors to maintain long-term unauthorized access to a system, execute arbitrary payloads with elevated permissions, or bypass basic security controls. This activity is a common precursor to wider network compromise, data exfiltration, or ransomware deployment. Organizations may face significant operational disruption and data loss if persistent malicious tasks remain undetected.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Enable Windows Security Event Log auditing for Task Scheduler events (Event IDs 4698, 4700, 4702) across all endpoints.</li>
<li>Implement a centralized watchlist of suspicious task names derived from threat intelligence to flag anomalous registrations.</li>
<li>Investigate any scheduled task creation that includes shell commands or binary execution paths from suspicious directories (e.g., Temp, AppData).</li>
<li>Use the provided drilldown searches to correlate alerts with user identity and system context to distinguish between administrative tasks and malicious activity.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>persistence</category><category>scheduled-tasks</category><category>windows</category><category>detection-engineering</category></item></channel></rss>