{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/task-scheduler/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["persistence","privilege-escalation","execution","windows","task-scheduler"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThreat actors consistently abuse the Windows Task Scheduler to achieve persistence, privilege escalation, and lateral movement. By utilizing 'schtasks.exe', attackers can register tasks that trigger malicious activity on system startup, login, or at periodic intervals. Defenders have observed a variety of malicious patterns associated with this technique, ranging from basic command-line execution (e.g., 'cmd /c') to complex, obfuscated PowerShell one-liners and the use of system binaries like 'mshta.exe' or 'cscript.exe'.\u003c/p\u003e\n\u003cp\u003eAttackers frequently place the target executable in writeable, non-standard directories such as 'C:\\ProgramData\\', 'C:\\Temp\\', or user-specific 'AppData' folders to bypass restrictions on protected system directories. Monitoring the command-line arguments of 'schtasks.exe' is critical for detecting these malicious task registrations, as the presence of high-frequency task triggers, privileged account execution, or suspicious scripting indicators often points to automated malware deployment or post-exploitation activities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of the Windows Task Scheduler allows attackers to ensure their malware persists across system reboots, execute payloads with SYSTEM privileges, and automate the exfiltration of sensitive data. This technique is pervasive across malware families, including ransomware and sophisticated backdoors, often serving as a foundational step for long-term environment compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious 'schtasks.exe' command-line patterns in process creation telemetry.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon or equivalent EDR process creation logging with command-line auditing to capture the full execution scope of 'schtasks.exe'.\u003c/li\u003e\n\u003cli\u003eTune the detection to account for legitimate software installers, which may use temporary folders (like 'C:\\Temp\\') for setup tasks during an initial deployment window.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for automated administrative task creation to minimize false positives from legitimate IT management tools.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:44:26Z","date_published":"2026-09-03T12:44:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-suspicious-schtasks-patterns/","summary":"Adversaries frequently leverage scheduled tasks to maintain persistence or execute malicious payloads by invoking commands from temporary directories or utilizing obfuscated PowerShell/scripting patterns.","title":"Suspicious Command Patterns in Scheduled Task Creation","url":"https://feed.craftedsignal.io/briefs/2026-09-suspicious-schtasks-patterns/"}],"language":"en","title":"CraftedSignal Threat Feed - Task-Scheduler","version":"https://jsonfeed.org/version/1.1"}