T1053 Scheduled Task/Job — ATT&CK Technique
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system. Adversaries may use task scheduling to execute programs at system startup or on a scheduled basis for persistence. These mechanisms can also be abused to run a process under the context of a specified account (such as one with elevated permissions/privileges). Similar to System Binary Proxy Execution, adversaries have also abused task scheduling to potentially mask one-time execution under a trusted system process.
Detection coverage (19)
- Defrag Deactivation - Security medium
- HAFNIUM Exchange Exploitation Activity critical
- Potential ACTINIUM Persistence Activity high
- Remote Schedule Task Lateral Movement via ATSvc high
- Remote Schedule Task Lateral Movement via ITaskSchedulerService high
- Remote Schedule Task Lateral Movement via SASec high
- Cisco Modify Configuration medium
- Suspicious Scheduled Task Write to System32 Tasks high
- HackTool - CrackMapExec Execution Patterns high
- HackTool - CrackMapExec Execution high
- HackTool - SharPersist Execution high
- Scheduled TaskCache Change by Uncommon Program high
- Schedule Task with Rundll32 Command Trigger
- Schedule Task with HTTP Command Arguments
- Schtasks Run Task On Demand
- Windows Hidden Schedule Task Settings
- Windows Level RMM Watchdog Task Created
- Windows Scheduled Task DLL Module Loaded
- Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr