Suspicious Process Execution From Windows Tasks Directory

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects process execution from the C\Windows\Tasks directory, an atypical location for legitimate executables. A malicious npm package delivering the AdaptixC2 agent staged its Windows payload in C\Windows\Tasks alongside a sideloaded msdtc.exe DLL. Because the Tasks folder is normally used only for legacy scheduled task metadata, running a binary from there strongly suggests payload staging and defense evasion.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious Execution From Hidden fonts-unix Directory in tmp on Linux
Suspicious tmp Download and Execute Chain on Embedded Linux
Malicious CiscoCollabHost Execution From AppData Path via process_creation
Malicious ViPNet Backdoor Loader via lumpdiag.exe Path Substitution
Suspicious msinfo32.exe Executed From ViPNet Update Directory
Suspicious Curl Download to Update Executable during FortiClient EMS Exploitation
Suspicious DLL Side-Loading Host Binary Executed Outside System32 by Lazarus
Suspicious RC4 DLL Sideloading via rundll32 by Tropic Trooper
Suspicious File Download via certutil urlcache
Suspicious Process Execution From Windows Tasks Directory
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.