Suspicious Scheduled Task Creation in Public Writable Directory via schtasks (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-03
Updated
2026-10-03

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects schtasks being launched by cmd or PowerShell to create a scheduled task that points at a payload located in a world-writable directory such as Users Public, PerfLogs or ProgramData. This pattern is used by SocGholish to persist a recurring task that executes staged tooling, indicating establishment of scheduled-task persistence.

Related detections9 linkedT1053.005 — drag to rearrange
Suspicious Scheduled Task Executing Payload from AppData
Suspicious Scheduled Task Running PowerShell Every Minute (via process_creation)
Scheduled Task Creating Per-Minute Hidden PowerShell Execution
Windows Process Creation: schtasks.exe Creating Scheduled Task Launching Registry-Stored PowerShell Payload
Windows Task Scheduler persistence using svchost-launched PowerShell with hidden/Bypass flags
Windows schtasks.exe Create Executes File from AppData\Local
Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Windows ChromeLoader Execution via Scheduled Task and Hidden PowerShell Launch
Windows process command lines matching May 2020 Turla ComRAT command patterns
Suspicious Scheduled Task Creation in Public Writable Directory via schtasks (via process_creation)
Pivot detection · T1053.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.