Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)

Identifies remote ATSvc RPC calls for scheduled task creation/execution using RPC Firewall EventID 3 and OpNum 0/1.

FreeReviewedSigma · High · v5
Product
rpc_firewall
Category
application
Author
Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies remote RPC requests to the ATSvc interface that map to creating or executing scheduled tasks. Attackers can use ATSvc-driven scheduled tasks for execution and persistence while moving laterally between systems. Detection relies on RPC Firewall application logs (EventLog RPCFW) capturing EventID 3 for the specific InterfaceUuid and operation numbers 0 and 1.

Related detections9 linkedT1053 — drag to rearrange
Remote ITaskSchedulerService RPC Create/Execute Scheduled Tasks Used for Lateral Movement
RPC Firewall Alerts for Remote Scheduled Task Creation/Execution via SASec
Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Windows process creation: CrackMapExec execution via characteristic command-line flags
Windows Process Creation: Scheduled Task Creation via schtasks and wscript/vbscript
Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Windows Registry: New TaskCache entry created by unusual process image
Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)
Pivot detection · T1053 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.