Windows Schtasks Execution with Renamed schtasks.exe Binary
Alerts on scheduled task management commands that use a renamed schtasks.exe binary on Windows.
FreeUnreviewedSigmahighv1
windows-schtasks-execution-with-renamed-schtasks-exe-binary-f91e51c9
title: Windows Schtasks Execution with Renamed schtasks.exe Binary
id: 2179894d-58fa-461e-913d-9a61201f3014
status: experimental
description: This rule flags process creation where schtasks functionality is invoked via command-line parameters commonly used for creating, modifying, deleting, querying, running, or ending scheduled tasks, but the executed binary name does not match the expected schtasks.exe path. Attackers often rename legitimate binaries to reduce the likelihood of security tooling detecting task scheduling activity. The detection relies on Windows process creation telemetry, including the process Image/OriginalFileName and the CommandLine containing schtasks-related flags and operations.
references:
- https://x.com/JangPr0/status/1932034543026065833
- https://ss64.com/nt/schtasks.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_renamed_schtasks_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-27
tags:
- attack.execution
- attack.persistence
- attack.privilege-escalation
- attack.stealth
- attack.t1036.003
- attack.t1053.005
logsource:
category: process_creation
product: windows
detection:
selection_cmd_operation:
CommandLine|contains|windash:
- " /create "
- " /delete "
- " /query "
- " /change "
- " /run "
- " /end "
selection_cmd_flags:
CommandLine|contains|windash:
- " /tn "
- " /tr "
- " /sc "
- " /st "
- " /ru "
- " /fo "
selection_pe:
OriginalFileName: schtasks.exe
filter_main_cmd:
CommandLine|contains: schtasks
filter_main_img:
Image|endswith: \schtasks.exe
condition: (all of selection_cmd_* and not filter_main_cmd) or (selection_pe and not filter_main_img)
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: f91e51c9-f344-4b32-969b-0b6f6b8537d4
type: derived
What it detects
This rule flags process creation where schtasks functionality is invoked via command-line parameters commonly used for creating, modifying, deleting, querying, running, or ending scheduled tasks, but the executed binary name does not match the expected schtasks.exe path. Attackers often rename legitimate binaries to reduce the likelihood of security tooling detecting task scheduling activity. The detection relies on Windows process creation telemetry, including the process Image/OriginalFileName and the CommandLine containing schtasks-related flags and operations.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.