Windows Scheduled Task Creation with Schtasks -XML Using Non-.xml File

Alerts when schtasks.exe creates a scheduled task using -XML but the referenced file does not end with .xml.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel, Elastic (idea) (SigmaHQ), DRL 1.1
Published
2023-04-20
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags process creation where schtasks.exe is invoked with /create and the /xml argument, but the command line does not include a .xml file extension. Attackers may use this masquerading technique to hide scheduled task payloads and improve persistence while blending into expected task creation activity. It relies on Windows process creation telemetry, including the executable name, command line arguments, and integrity level and parent process context to reduce likely benign cases.

Related detections9 linkedT1053.005 — drag to rearrange
Suspicious Scheduled Task Masquerading As System Process
Malicious Scheduled Task Masquerading as Google Updater via Schtasks
Suspicious Scheduled Task SystemSoundsService2 Creation via Process Creation
Windows Scheduled Task Creation Using System Process Names
Suspicious ALPHA SPIDER Rclone Exfiltration Tool Masquerading as System Binary (via process_creation)
Malicious CloudZ RAT Persistence via schtasks Running regasm.exe
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Suspicious Scheduled Task Creation for WSPrint Persistence by UAT-9244
Malicious Scheduled Task Masquerading as GoogleUpdate Launching SSH Reverse Shell
Windows Scheduled Task Creation with Schtasks -XML Using Non-.xml File
Pivot detection · T1053.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.