Windows Scheduled Task Creation Using SVR-Specific Task Names

Alerts on Windows scheduled task events with SVR-associated task names indicative of persistence.

FreeReviewedSigma · High · v5
Product
windows
Service
security
Author
CISA (SigmaHQ), DRL 1.1
Published
2023-12-18
Updated
2026-07-31

What it detects

This rule flags Windows security events where scheduled task operations (creation, update, or assignment) reference a set of SVR-specific task names. Attackers may use scheduled tasks to persist or periodically execute malicious components, making these task name patterns useful for early compromise hunting. It relies on Windows Security audit events 4698, 4699, and 4702 with the corresponding TaskName field matching the listed values.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.