RPC Firewall Alerts for Remote Scheduled Task Creation/Execution via SASec

Identifies remote scheduled task create/execute RPC calls via SASec using RPC Firewall EventLog RPCFW events.

FreeReviewedSigma · High · v5
Product
rpc_firewall
Category
application
Author
Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags RPC Firewall EventLog entries indicating remote SASec (Task Scheduler) operations to create or execute scheduled tasks. Attackers can abuse scheduled tasks for execution and persistence while moving laterally across systems. It relies on RPC Firewall telemetry (EventLog entries with EventID 3) matched to a specific Task Scheduler interface UUID and operation numbers 0 and 1.

Related detections9 linkedT1053 — drag to rearrange
Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)
Remote ITaskSchedulerService RPC Create/Execute Scheduled Tasks Used for Lateral Movement
Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Windows process creation: CrackMapExec execution via characteristic command-line flags
Windows Process Creation: Scheduled Task Creation via schtasks and wscript/vbscript
Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Windows Registry: New TaskCache entry created by unusual process image
Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
RPC Firewall Alerts for Remote Scheduled Task Creation/Execution via SASec
Pivot detection · T1053 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.