Windows Security Event Detection: GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Write
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
FreeUnreviewedSigmahighv1
windows-security-event-detection-gpo-scheduled-task-persistence-via-sysvol-sched-a8f29a7b
title: "Windows Security Event Detection: GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Write"
id: 6862793a-49f7-4887-afb1-2466082c39ee
status: test
description: This rule flags Windows security events indicating GPO modifications that write ScheduledTasks.xml into SYSVOL, enabling scheduled task deployment across machines. Attackers use this mechanism for persistence and lateral execution at scale by distributing task definitions through Group Policy. The detection relies on EventID 5136 and 5145 telemetry for specific GPO extension identifiers and write access patterns to SYSVOL\ScheduledTasks.xml.
references:
- https://twitter.com/menasec1/status/1106899890377052160
- https://www.secureworks.com/blog/ransomware-as-a-distraction
- https://www.elastic.co/guide/en/security/7.17/prebuilt-rule-0-16-1-scheduled-task-execution-at-scale-via-gpo.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_gpo_scheduledtasks.yml
author: Samir Bousseaden, Huntrule Team
date: 2019-04-03
modified: 2024-09-04
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.lateral-movement
- attack.t1053.005
logsource:
product: windows
service: security
definition: The advanced audit policy setting "Object Access > Audit Detailed File Share" must be configured for Success/Failure
detection:
selection_5136:
EventID: 5136
AttributeLDAPDisplayName:
- gPCMachineExtensionNames
- gPCUserExtensionNames
AttributeValue|contains:
- CAB54552-DEEA-4691-817E-ED4A4D1AFC72
- AADCED64-746C-4633-A97C-D61349046527
selection_5145:
EventID: 5145
ShareName|endswith: \SYSVOL
RelativeTargetName|endswith: ScheduledTasks.xml
AccessList|contains:
- WriteData
- "%%4417"
condition: 1 of selection_*
falsepositives:
- If the source IP is not localhost then it's super suspicious, better to monitor both local and remote changes to GPO scheduled tasks.
level: high
license: DRL-1.1
related:
- id: a8f29a7b-b137-4446-80a0-b804272f3da2
type: derived
What it detects
This rule flags Windows security events indicating GPO modifications that write ScheduledTasks.xml into SYSVOL, enabling scheduled task deployment across machines. Attackers use this mechanism for persistence and lateral execution at scale by distributing task definitions through Group Policy. The detection relies on EventID 5136 and 5145 telemetry for specific GPO extension identifiers and write access patterns to SYSVOL\ScheduledTasks.xml.
Known false positives
- If the source IP is not localhost then it's super suspicious, better to monitor both local and remote changes to GPO scheduled tasks.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.