Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables
Alerts when schtasks.exe creates tasks whose target path/arguments reference suspicious folders or common environment variables.
FreeUnreviewedSigmamediumv1
windows-schtasks-exe-task-creation-targeting-suspicious-paths-or-env-variables-81325ce1
title: Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables
id: 7a56e7dc-3ca3-4fe6-a810-1dfc9b02de1a
related:
- id: 43f487f0-755f-4c2a-bce7-d6d2eec2fcf8
type: derived
- id: 81325ce1-be01-4250-944f-b4789644556f
type: derived
status: test
description: This rule flags Windows process executions where schtasks.exe is used with /create and the command line references potentially suspicious directories or environment variables frequently abused in persistence and execution. Attackers may schedule tasks to run payloads while blending into normal host activity, so focusing on unusual target paths improves signal quality. It relies on process creation telemetry, including the schtasks.exe image path, command-line arguments, and the parent process command line for the Windows Schedule service.
references:
- https://www.welivesecurity.com/2022/01/18/donot-go-do-not-respawn/
- https://www.joesandbox.com/analysis/514608/0/html#324415FF7D8324231381BAD48A052F85DF04
- https://blog.talosintelligence.com/gophish-powerrat-dcrat/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_schtasks_env_folder.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-02-21
modified: 2025-10-07
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.t1053.005
logsource:
product: windows
category: process_creation
detection:
selection_1_create:
Image|endswith: \schtasks.exe
CommandLine|contains|windash: " /create "
selection_1_all_folders:
CommandLine|contains:
- :\Perflogs
- :\Users\All Users\
- :\Users\Default\
- :\Users\Public
- :\Windows\Temp
- \AppData\Local\
- \AppData\Roaming\
- "%AppData%"
- "%Public%"
selection_2_parent:
ParentCommandLine|endswith: \svchost.exe -k netsvcs -p -s Schedule
selection_2_some_folders:
CommandLine|contains:
- :\Perflogs
- :\Windows\Temp
- \Users\Public
- "%Public%"
filter_optional_other:
- ParentCommandLine|contains: unattended.ini
- CommandLine|contains: update_task.xml
filter_optional_team_viewer:
CommandLine|contains: /Create /TN TVInstallRestore /TR
filter_optional_avira_install:
CommandLine|contains|all:
- "/Create /Xml "
- \Temp\.CR.
- \Avira_Security_Installation.xml
filter_optional_avira_other:
CommandLine|contains|all:
- /Create /F /TN
- "/Xml "
- \Temp\
- Avira_
CommandLine|contains:
- .tmp\UpdateFallbackTask.xml
- .tmp\WatchdogServiceControlManagerTimeout.xml
- .tmp\SystrayAutostart.xml
- .tmp\MaintenanceTask.xml
filter_optional_klite_codec:
CommandLine|contains|all:
- \Temp\
- '/Create /TN "klcp_update" /XML '
- \klcp_update_task.xml
condition: ( all of selection_1_* or all of selection_2_* ) and not 1 of filter_optional_*
falsepositives:
- Benign scheduled tasks creations or executions that happen often during software installations
- Software that uses the AppData folder and scheduled tasks to update the software in the AppData folders
level: medium
license: DRL-1.1
What it detects
This rule flags Windows process executions where schtasks.exe is used with /create and the command line references potentially suspicious directories or environment variables frequently abused in persistence and execution. Attackers may schedule tasks to run payloads while blending into normal host activity, so focusing on unusual target paths improves signal quality. It relies on process creation telemetry, including the schtasks.exe image path, command-line arguments, and the parent process command line for the Windows Schedule service.
Known false positives
- Benign scheduled tasks creations or executions that happen often during software installations
- Software that uses the AppData folder and scheduled tasks to update the software in the AppData folders
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.