Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)

Alerts when scheduled task and Service.exe processes launch autoit3.exe that runs nslookup TXT queries from a temp staging path.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2018-03-23
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. Exfiltration

  10. Impact

What it detects

This rule flags Windows process activity consistent with automated execution via a scheduled task that runs local\microsoft\Taskbar\autoit3.exe. The pattern includes task-related command lines, execution from \\Windows\\Temp\\DB\\, and a child process invoking nslookup.exe with "-q=TXT". Attackers may use this combination to stage tooling and perform DNS-based communications or checks, relying on process creation telemetry with command line and parent process details.

Related detections9 linkedT1112 — drag to rearrange
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Windows Registry Persistence via UMe/UT Run Keys
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Hidden Scheduled Task via TaskCache Security Descriptor Manipulation
Suspicious Windows Service Trigger Configuration via Registry Modification
Suspicious Service Persistence Masquerading as DevQueryBrokerService
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Pivot detection · T1112 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.