T1053.005 Scheduled Task — ATT&CK Technique
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path. An adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to System Binary Proxy Execution, adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes. Adversaries may also create "hidden" scheduled tasks (i.e. Hide Artifacts) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions). Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.
Detection coverage (50)
- Diamond Sleet APT Scheduled Task Creation critical
- Kapeka Backdoor Persistence Activity high
- Kapeka Backdoor Scheduled Task Creation high
- Scheduled Task Deletion low
- Scheduled Task Created - FileCreation low
- Task Scheduler DLL Loaded By Application Located In Potentially Suspicious Location low
- Scheduled Task Created - Registry low
- Scheduled Task Creation From Potential Suspicious Parent Location medium
- Persistence and Execution at Scale via GPO Scheduled Task high
- Suspicious Scheduled Task Update high
- Important Scheduled Task Deleted/Disabled high
- Suspicious Scheduled Task Creation high
- Scheduled Task Executed Uncommon LOLBIN medium
- Scheduled Task Executed From A Suspicious Location medium
- Powershell Create Scheduled Task medium
- HackTool - Default PowerSploit/Empire Scheduled Task Creation high
- Renamed Schtasks Execution high
- Scheduled Task Creation Via Schtasks.EXE low
- Potential SSH Tunnel Persistence Install Using A Scheduled Task high
- Suspicious Modification Of Scheduled Tasks high
- Suspicious Scheduled Task Creation Involving Temp Folder high
- Suspicious Scheduled Task Name As GUID medium
- Scheduled Task Executing Payload from Registry medium
- Suspicious Schtasks Execution AppData Folder high
- Schtasks From Suspicious Folders high
- Potential Persistence Via Powershell Search Order Hijacking - Task high
- Suspicious Scheduled Task Creation via Masqueraded XML File medium
- Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE medium
- Potential Persistence Via Microsoft Compatibility Appraiser medium
- Suspicious Schtasks Schedule Type With High Privileges medium
- Scheduled Task Creation with Curl and PowerShell Execution Combo medium
- Uncommon One Time Only Scheduled Task At 00:00 high
- Scheduled Task Executing Encoded Payload from Registry high
- Schtasks Creation Or Modification With SYSTEM Privileges high
- Suspicious Schtasks Schedule Types high
- Scheduled Task Creation Masquerading as System Processes high
- Suspicious Command Patterns In Scheduled Task Creation high
- Scheduled TaskCache Change by Uncommon Program high
- Potential Registry Persistence Attempt Via Windows Telemetry high
- Possible Lateral Movement PowerShell Spawn
- Randomly Generated Scheduled Task Name
- Scheduled Task Deleted Or Created via CMD
- Schtasks scheduling job on remote system
- Scheduled Task Initiation on Remote Endpoint
- Schtasks used for forcing a reboot
- Short Lived Scheduled Task
- Suspicious Scheduled Task from Public Directory
- Svchost LOLBAS Execution Process Spawn
- Turla Group Commands May 2020 critical
- Windows Compatibility Telemetry Suspicious Child Process
Malware using this technique
- TrickBot
- Bumblebee
- GRIFFON
- yty
- Stuxnet
- MagicRAT
- POWRUNER
- SharpStage
- Smoke Loader
- Matryoshka
- GravityRAT
- Prestige
- SharpDisco
- TONESHELL
- RainyDay
- NETWIRE
- SQLRat
- LitePower
- Bad Rabbit
- CosmicDuke
- IMAPLoader
- Emotet
- Tomiris
- BADHATCH
- Machete
- PUBLOAD
- SystemBC
- DarkWatchman
- InvisiMole
- CLAIMLOADER
- Apostle
- Okrum
- SameCoin
- RemoteCMD
- IcedID
- Nightdoor
- CHIMNEYSWEEP
- Lucifer
- zwShell
- NotPetya
- GoldMax
- Anchor
- Pteranodon
- Bazar
- SUGARDUMP
- Dyre
- PlugX
- MultiLayer Wiper
- Remsec
- EvilBunny
Threat actors using this technique
- Crypto24
- Storm-2603
- HEXANE
- Daggerfly
- Rancor
- APT38
- BlackByte
- GALLIUM
- APT3
- Kimsuky
- Patchwork
- APT41
- Dragonfly
- APT10
- APT32
- MuddyWater
- Naikon
- FIN6
- Gamaredon Group
- FIN7
- Sandworm Team
- Machete
- Mustang Panda
- APT35
- APT39
- TA2541
- APT37
- OilRig
- Higaisa
- Confucius
- Blue Mockingbird
- Winter Vivern
- Storm-0501
- BITTER
- RedCurl
- Stealth Falcon
- APT29
- Chimera
- BRONZE BUTLER
- APT33
- FIN10
- FIN8
- Ember Bear
- ToddyCat
- LuminousMoth
- APT42
- Fox Kitten
- APT-C-36
- Lazarus Group
- Earth Lusca