Windows Registry Scheduled Task Cache Key Creation Detection

Flags registry event activity under Scheduled TaskCache indicating scheduled task creation or updates on Windows.

FreeReviewedSigma · Low · v5
Product
windows
Category
registry_event
Author
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team (SigmaHQ), DRL 1.1
Published
2023-09-27
Updated
2026-07-31
title: Windows Registry Scheduled Task Cache Key Creation Detection
id: 136a2855-cb13-4156-9468-ecd1a5c58612
status: test
description: This rule detects new Windows Registry entries under the TaskCache Tasks and Tree paths used for scheduled task caching. Attackers can leverage scheduled tasks for persistence by creating or updating tasks and their cached state, so monitoring these registry keys can reveal suspicious scheduling activity. It relies on registry event telemetry that records writes to Windows Registry locations matching the specified TaskCache subpaths.
references:
  - https://center-for-threat-informed-defense.github.io/summiting-the-pyramid/analytics/task_scheduling/
  - https://posts.specterops.io/abstracting-scheduled-tasks-3b6451f6a1c5
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/registry/registry_event/registry_event_scheduled_task_creation.yml
author: Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule Team
date: 2023-09-27
tags:
  - attack.execution
  - attack.persistence
  - attack.privilege-escalation
  - attack.s0111
  - attack.t1053.005
  - car.2013-08-001
  - detection.threat-hunting
logsource:
  product: windows
  category: registry_event
detection:
  selection:
    TargetObject|contains:
      - \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\
      - \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\
  condition: selection
falsepositives:
  - Likely as this is a normal behaviour on Windows
level: low
license: DRL-1.1
related:
  - id: 93ff0ceb-e0ef-4586-8cd8-a6c277d738e3
    type: derived