RPC Firewall: Remote Scheduled Task Recon via ITaskSchedulerService (OpNum 1/3/4/10-15)

Flags RPC calls to ITaskSchedulerService that query scheduled task information using RPC firewall telemetry.

FreeReviewedSigma · High · v5
Product
rpc_firewall
Category
application
Author
Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-31

What it detects

This rule flags RPC Firewall EventLog entries indicating remote RPC requests to the ITaskSchedulerService interface that are consistent with scheduled task information discovery. Such recon can be used to enumerate task-related data before further actions, making it valuable for detecting attacker staging. It relies on RPC Firewall telemetry (EventLog RPCFW, EventID 3) matched to a specific InterfaceUuid and unfiltered operation numbers (OpNum).

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.