Windows Registry Scheduled Task Cache Key Creation Detection
Flags registry event activity under Scheduled TaskCache indicating scheduled task creation or updates on Windows.
- Product
- windows
- Category
- registry_event
- Author
- Center for Threat Informed Defense (CTID) Summiting the Pyramid Team (SigmaHQ), DRL 1.1
- Published
- 2023-09-27
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule detects new Windows Registry entries under the TaskCache Tasks and Tree paths used for scheduled task caching. Attackers can leverage scheduled tasks for persistence by creating or updating tasks and their cached state, so monitoring these registry keys can reveal suspicious scheduling activity. It relies on registry event telemetry that records writes to Windows Registry locations matching the specified TaskCache subpaths.
Reporting behind it
- center-for-threat-informed-defense.github.iohttps://center-for-threat-informed-defense.github.io/summiting-the-pyramid/analytics/task_scheduling/
- posts.specterops.iohttps://posts.specterops.io/abstracting-scheduled-tasks-3b6451f6a1c5
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/registry/registry_event/registry_event_scheduled_task_creation.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Scheduled Task Cache Key Creation Detection
id: 136a2855-cb13-4156-9468-ecd1a5c58612
status: test
description: This rule detects new Windows Registry entries under the TaskCache Tasks and Tree paths used for scheduled task caching. Attackers can leverage scheduled tasks for persistence by creating or updating tasks and their cached state, so monitoring these registry keys can reveal suspicious scheduling activity. It relies on registry event telemetry that records writes to Windows Registry locations matching the specified TaskCache subpaths.
references:
- https://center-for-threat-informed-defense.github.io/summiting-the-pyramid/analytics/task_scheduling/
- https://posts.specterops.io/abstracting-scheduled-tasks-3b6451f6a1c5
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/registry/registry_event/registry_event_scheduled_task_creation.yml
author: Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule Team
date: 2023-09-27
tags:
- attack.execution
- attack.persistence
- attack.privilege-escalation
- attack.s0111
- attack.t1053.005
- car.2013-08-001
- detection.threat-hunting
logsource:
product: windows
category: registry_event
detection:
selection:
TargetObject|contains:
- \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\
- \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\
condition: selection
falsepositives:
- Likely as this is a normal behaviour on Windows
level: low
license: DRL-1.1
related:
- id: 93ff0ceb-e0ef-4586-8cd8-a6c277d738e3
type: derived