Scheduled Task

T1053.005

Sub-technique of T1053 Scheduled Task/Job.View on attack.mitre.org

About this technique

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

An adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to System Binary Proxy Execution, adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.

Adversaries may also create "hidden" scheduled tasks (i.e. Hide Artifacts) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions). Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.

Detection rules57

Rules on DetectionCode tagged with T1053.005.

Sigma31

RuleLevelLog source
HackTool - Default PowerSploit/Empire Scheduled Task Creationhighwindows / process_creation
Important Scheduled Task Deleted/Disabledhighwindows / NULL
Persistence and Execution at Scale via GPO Scheduled Taskhighwindows / NULL
Potential Persistence Via Powershell Search Order Hijacking - Taskhighwindows / process_creation
Potential Registry Persistence Attempt Via Windows Telemetryhighwindows / registry_set
Potential SSH Tunnel Persistence Install Using A Scheduled Taskhighwindows / process_creation
Renamed Schtasks Executionhighwindows / process_creation
Scheduled Task Creation Masquerading as System Processeshighwindows / process_creation
Scheduled Task Executing Encoded Payload from Registryhighwindows / process_creation
Scheduled TaskCache Change by Uncommon Programhighwindows / registry_set
Schtasks Creation Or Modification With SYSTEM Privilegeshighwindows / process_creation
Schtasks From Suspicious Foldershighwindows / process_creation
Suspicious Command Patterns In Scheduled Task Creationhighwindows / process_creation
Suspicious Modification Of Scheduled Taskshighwindows / process_creation
Suspicious Scheduled Task Creationhighwindows / NULL

Splunk26

RuleTypeRiskData source
Possible Lateral Movement PowerShell SpawnAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Randomly Generated Scheduled Task NameHuntingNULLWindows Event Log Security 4698
Scheduled Task Deleted Or Created via CMDAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Scheduled Task Initiation on Remote EndpointTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Scheduled tasks used in BadRabbit ransomwareTTPNULLSysmon EventID 1
Schtasks scheduling job on remote systemTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Schtasks used for forcing a rebootTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Short Lived Scheduled TaskAnomalyNULLWindows Event Log Security 4698, Windows Event Log Security 4699
Suspicious Scheduled Task from Public DirectoryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Svchost LOLBAS Execution Process SpawnTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Compatibility Telemetry Suspicious Child ProcessTTPNULLWindows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
Windows Compatibility Telemetry Tampering Through RegistryTTPNULLSysmon EventID 13
Windows Enable Win32 ScheduledJob via RegistryAnomalyNULLSysmon EventID 13
Windows Error Report Created in ReportQueue ManuallyAnomalyNULLSysmon EventID 11
Windows PowerShell ScheduleTaskAnomalyNULLPowershell Script Block Logging 4104

Groups54

Show 30 more

Software124

Show 100 more

Campaigns12

Procedure examples190

Groups54

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.

GroupAPT29

APT29 has used named and hijacked scheduled tasks to establish persistence.

GroupAPT3

An APT3 downloader creates persistence by creating the following scheduled task: schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System".

GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

GroupAPT33

APT33 has created a scheduled task to execute a .vbe file multiple times a day.

GroupAPT37

APT37 has created scheduled tasks to run malicious scripts on a compromised host.

GroupAPT38

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

GroupAPT39

APT39 has created scheduled tasks for persistence.

View all 54 groups examples

Software124

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has achieved persistence via scheduled tasks.

MalwareAnchor

Anchor can create a scheduled task for persistence.

MalwareApostle

Apostle achieves persistence by creating a scheduled task, such as MicrosoftCrashHandlerUAC.

MalwareAppleJeus

AppleJeus has created a scheduled SYSTEM task that runs when a user logs in.

MalwareAshTag

AshTag can set persistence using scheduled tasks.

ToolAsyncRAT

AsyncRAT can create a scheduled task to maintain persistence on system start-up.

MalwareAttor

Attor's installer plugin can schedule a new task that loads the dispatcher on boot/logon.

MalwareBabyShark

BabyShark has used scheduled tasks to maintain persistence.

View all 124 software examples

Campaigns12

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

CampaignC0017

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

CampaignC0032

During the C0032 campaign, TEMP.Veles used scheduled task XML triggers.

CampaignCostaRicto

During CostaRicto, the threat actors used scheduled tasks to download backdoor tools.

CampaignFrankenstein

During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate"

CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.`

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.

View all 12 campaigns examples

References6

  1. Defending Against Scheduled Task Attacks in Windows Environments Open source
    Harshal Tupsamudre. (2022, June 20). Defending Against Scheduled Tasks. Retrieved July 5, 2022.
  2. ProofPoint Serpent Open source
    Campbell, B. et al. (2022, March 21). Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain. Retrieved April 11, 2022.
  3. Red Canary - Atomic Red Team Open source
    Red Canary - Atomic Red Team. (n.d.). T1053.005 - Scheduled Task/Job: Scheduled Task. Retrieved June 19, 2024.
  4. SigmaHQ Open source
    Sittikorn S. (2022, April 15). Removal Of SD Value to Hide Schedule Task - Registry. Retrieved June 1, 2022.
  5. Stack Overflow Open source
    Stack Overflow. (n.d.). How to find the location of the Scheduled Tasks folder. Retrieved June 19, 2024.
  6. Tarrask scheduled task Open source
    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.