Windows Suspicious Scheduled Task File Write Targeting System32 Tasks

Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-11-16
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies file activity where a process writes to paths under \Windows\System32\Tasks and the writing process executable is located in or originates from suspicious locations such as \AppData\, C:\PerfLogs, or \Windows\System32\config\systemprofile. Attackers often use scheduled tasks for persistence or privilege-related execution, and writing task definitions to this location is a key indicator of that behavior. It relies on Windows file event telemetry capturing both the target filename path and the source process image path.

Related detections9 linkedT1053 — drag to rearrange
Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Windows process creation: CrackMapExec execution via characteristic command-line flags
Windows Process Creation: Scheduled Task Creation via schtasks and wscript/vbscript
Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)
Remote ITaskSchedulerService RPC Create/Execute Scheduled Tasks Used for Lateral Movement
RPC Firewall Alerts for Remote Scheduled Task Creation/Execution via SASec
Windows Registry: New TaskCache entry created by unusual process image
Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Pivot detection · T1053 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.