Sub-technique of T1053 Scheduled Task/Job.View on attack.mitre.org
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
An adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to System Binary Proxy Execution, adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.
Adversaries may also create "hidden" scheduled tasks (i.e. Hide Artifacts) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions). Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.
Rules on DetectionCode tagged with T1053.005.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Randomly Generated Scheduled Task Name | Hunting | NULL | Windows Event Log Security 4698 |
| Scheduled Task Deleted Or Created via CMD | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Scheduled Task Initiation on Remote Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Scheduled tasks used in BadRabbit ransomware | TTP | NULL | Sysmon EventID 1 |
| Schtasks scheduling job on remote system | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Schtasks used for forcing a reboot | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Short Lived Scheduled Task | Anomaly | NULL | Windows Event Log Security 4698, Windows Event Log Security 4699 |
| Suspicious Scheduled Task from Public Directory | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Svchost LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Compatibility Telemetry Suspicious Child Process | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Compatibility Telemetry Tampering Through Registry | TTP | NULL | Sysmon EventID 13 |
| Windows Enable Win32 ScheduledJob via Registry | Anomaly | NULL | Sysmon EventID 13 |
| Windows Error Report Created in ReportQueue Manually | Anomaly | NULL | Sysmon EventID 11 |
| Windows PowerShell ScheduleTask | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Registry Delete Task SD | Anomaly | NULL | Sysmon EventID 12 |
| Windows Scheduled Task Created in a Group Policy Object | TTP | NULL | Windows Event Log Security 5145 |
| Windows Scheduled Task Created Via XML | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Scheduled Task Service Spawned Shell | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Scheduled Task with Highest Privileges | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Scheduled Task with Suspicious Command | TTP | NULL | Windows Event Log Security 4698, Windows Event Log Security 4700, Windows Event Log Security 4702 |
| Windows Scheduled Task with Suspicious Name | TTP | NULL | Windows Event Log Security 4698, Windows Event Log Security 4700, Windows Event Log Security 4702 |
| Windows Schtasks Create Run As System | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| WinEvent Scheduled Task Created to Spawn Shell | TTP | NULL | Windows Event Log Security 4698 |
| WinEvent Scheduled Task Created Within Public Path | TTP | NULL | Windows Event Log Security 4698 |
| WinEvent Windows Task Scheduler Event Action Started | Hunting | NULL | Windows Event Log TaskScheduler 200, Windows Event Log TaskScheduler 201 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google. |
| GroupAPT29 | APT29 has used named and hijacked scheduled tasks to establish persistence. |
| GroupAPT3 | An APT3 downloader creates persistence by creating the following scheduled task: |
| GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
| GroupAPT33 | APT33 has created a scheduled task to execute a .vbe file multiple times a day. |
| GroupAPT37 | APT37 has created scheduled tasks to run malicious scripts on a compromised host. |
| GroupAPT38 | APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task. |
| GroupAPT39 | APT39 has created scheduled tasks for persistence. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has achieved persistence via scheduled tasks. |
| MalwareAnchor | Anchor can create a scheduled task for persistence. |
| MalwareApostle | Apostle achieves persistence by creating a scheduled task, such as |
| MalwareAppleJeus | AppleJeus has created a scheduled SYSTEM task that runs when a user logs in. |
| MalwareAshTag | AshTag can set persistence using scheduled tasks. |
| ToolAsyncRAT | AsyncRAT can create a scheduled task to maintain persistence on system start-up. |
| MalwareAttor | Attor's installer plugin can schedule a new task that loads the dispatcher on boot/logon. |
| MalwareBabyShark | BabyShark has used scheduled tasks to maintain persistence. |
View all 124 software examples
| Used by | Procedure example |
|---|---|
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time. |
| CampaignC0017 | During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used scheduled task XML triggers. |
| CampaignCostaRicto | During CostaRicto, the threat actors used scheduled tasks to download backdoor tools. |
| CampaignFrankenstein | During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate" |
| CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.` |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.