Windows Scheduled Task Created via File Creation in System Task Directories
Flags file creation under Windows scheduled task directories that may indicate new scheduled task persistence.
FreeUnreviewedSigmalowv1
windows-scheduled-task-created-via-file-creation-in-system-task-directories-a762e74f
title: Windows Scheduled Task Created via File Creation in System Task Directories
id: 9e5dc11f-b31e-4fc6-84a1-913bf800313a
status: test
description: This rule identifies creation of files within Windows scheduled task directories, including the standard System32\Tasks, SysWOW64\Tasks, and Tasks locations. Attackers can abuse scheduled tasks for execution and persistence by placing task definition files where Windows expects them. The detection relies on Windows file event telemetry that includes the created file path (TargetFilename).
references:
- https://center-for-threat-informed-defense.github.io/summiting-the-pyramid/analytics/task_scheduling/
- https://posts.specterops.io/abstracting-scheduled-tasks-3b6451f6a1c5
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_event/file_event_win_scheduled_task_creation.yml
author: Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule Team
date: 2023-09-27
tags:
- attack.execution
- attack.persistence
- attack.privilege-escalation
- attack.t1053.005
- attack.s0111
- car.2013-08-001
- detection.threat-hunting
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains:
- :\Windows\System32\Tasks\
- :\Windows\SysWOW64\Tasks\
- :\Windows\Tasks\
condition: selection
falsepositives:
- Normal behaviour on Windows
level: low
license: DRL-1.1
related:
- id: a762e74f-4dce-477c-b023-4ed81df600f9
type: derived
What it detects
This rule identifies creation of files within Windows scheduled task directories, including the standard System32\Tasks, SysWOW64\Tasks, and Tasks locations. Attackers can abuse scheduled tasks for execution and persistence by placing task definition files where Windows expects them. The detection relies on Windows file event telemetry that includes the created file path (TargetFilename).
Known false positives
- Normal behaviour on Windows
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.