Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables

Alerts when schtasks.exe creates tasks whose target path/arguments reference suspicious folders or common environment variables.

FreeUnreviewedSigmamediumv1
title: Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables
id: 7a56e7dc-3ca3-4fe6-a810-1dfc9b02de1a
related:
  - id: 43f487f0-755f-4c2a-bce7-d6d2eec2fcf8
    type: derived
  - id: 81325ce1-be01-4250-944f-b4789644556f
    type: derived
status: test
description: This rule flags Windows process executions where schtasks.exe is used with /create and the command line references potentially suspicious directories or environment variables frequently abused in persistence and execution. Attackers may schedule tasks to run payloads while blending into normal host activity, so focusing on unusual target paths improves signal quality. It relies on process creation telemetry, including the schtasks.exe image path, command-line arguments, and the parent process command line for the Windows Schedule service.
references:
  - https://www.welivesecurity.com/2022/01/18/donot-go-do-not-respawn/
  - https://www.joesandbox.com/analysis/514608/0/html#324415FF7D8324231381BAD48A052F85DF04
  - https://blog.talosintelligence.com/gophish-powerrat-dcrat/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_schtasks_env_folder.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-02-21
modified: 2025-10-07
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.execution
  - attack.t1053.005
logsource:
  product: windows
  category: process_creation
detection:
  selection_1_create:
    Image|endswith: \schtasks.exe
    CommandLine|contains|windash: " /create "
  selection_1_all_folders:
    CommandLine|contains:
      - :\Perflogs
      - :\Users\All Users\
      - :\Users\Default\
      - :\Users\Public
      - :\Windows\Temp
      - \AppData\Local\
      - \AppData\Roaming\
      - "%AppData%"
      - "%Public%"
  selection_2_parent:
    ParentCommandLine|endswith: \svchost.exe -k netsvcs -p -s Schedule
  selection_2_some_folders:
    CommandLine|contains:
      - :\Perflogs
      - :\Windows\Temp
      - \Users\Public
      - "%Public%"
  filter_optional_other:
    - ParentCommandLine|contains: unattended.ini
    - CommandLine|contains: update_task.xml
  filter_optional_team_viewer:
    CommandLine|contains: /Create /TN TVInstallRestore /TR
  filter_optional_avira_install:
    CommandLine|contains|all:
      - "/Create /Xml "
      - \Temp\.CR.
      - \Avira_Security_Installation.xml
  filter_optional_avira_other:
    CommandLine|contains|all:
      - /Create /F /TN
      - "/Xml "
      - \Temp\
      - Avira_
    CommandLine|contains:
      - .tmp\UpdateFallbackTask.xml
      - .tmp\WatchdogServiceControlManagerTimeout.xml
      - .tmp\SystrayAutostart.xml
      - .tmp\MaintenanceTask.xml
  filter_optional_klite_codec:
    CommandLine|contains|all:
      - \Temp\
      - '/Create /TN "klcp_update" /XML '
      - \klcp_update_task.xml
  condition: ( all of selection_1_* or all of selection_2_* ) and not 1 of filter_optional_*
falsepositives:
  - Benign scheduled tasks creations or executions that happen often during software installations
  - Software that uses the AppData folder and scheduled tasks to update the software in the AppData folders
level: medium
license: DRL-1.1

What it detects

This rule flags Windows process executions where schtasks.exe is used with /create and the command line references potentially suspicious directories or environment variables frequently abused in persistence and execution. Attackers may schedule tasks to run payloads while blending into normal host activity, so focusing on unusual target paths improves signal quality. It relies on process creation telemetry, including the schtasks.exe image path, command-line arguments, and the parent process command line for the Windows Schedule service.

Known false positives

  • Benign scheduled tasks creations or executions that happen often during software installations
  • Software that uses the AppData folder and scheduled tasks to update the software in the AppData folders

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.