Potential SSH Tunnel Persistence Install Using A Scheduled Task

 Original Source: [Sigma source]
Title: Potential SSH Tunnel Persistence Install Using A Scheduled Task
Status: experimental
Description:Detects the creation of new scheduled tasks via commandline, using Schtasks.exe. This rule detects tasks creating that call OpenSSH, which may indicate the creation of reverse SSH tunnel to the attacker's server.
References:
  -https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
  -https://www.kroll.com/en/insights/publications/cyber/cactus-ransomware-prickly-new-variant-evades-detection
Author: Rory Duncan
Date: 2025-07-14
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.t1053.005'
  • -'attack.command-and-control'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\schtasks.exe' OriginalFileName:'schtasks.exe'   selection_cli_sshd:
    CommandLine|contains|all:
      -' /create '
      -'sshd.exe'
      -'-f'

  selection_cli_ssh:
    CommandLine|contains|all:
      -' /create '
      -'ssh.exe'
      -'-i'

  condition:selection_img and 1 of selection_cli_*
Falsepositives:
  -Unknown
Level: high