Windows Security Event Detection: GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Write

Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.

FreeUnreviewedSigmahighv1
title: "Windows Security Event Detection: GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Write"
id: 6862793a-49f7-4887-afb1-2466082c39ee
status: test
description: This rule flags Windows security events indicating GPO modifications that write ScheduledTasks.xml into SYSVOL, enabling scheduled task deployment across machines. Attackers use this mechanism for persistence and lateral execution at scale by distributing task definitions through Group Policy. The detection relies on EventID 5136 and 5145 telemetry for specific GPO extension identifiers and write access patterns to SYSVOL\ScheduledTasks.xml.
references:
  - https://twitter.com/menasec1/status/1106899890377052160
  - https://www.secureworks.com/blog/ransomware-as-a-distraction
  - https://www.elastic.co/guide/en/security/7.17/prebuilt-rule-0-16-1-scheduled-task-execution-at-scale-via-gpo.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_gpo_scheduledtasks.yml
author: Samir Bousseaden, Huntrule Team
date: 2019-04-03
modified: 2024-09-04
tags:
  - attack.privilege-escalation
  - attack.execution
  - attack.persistence
  - attack.lateral-movement
  - attack.t1053.005
logsource:
  product: windows
  service: security
  definition: The advanced audit policy setting "Object Access > Audit Detailed File Share" must be configured for Success/Failure
detection:
  selection_5136:
    EventID: 5136
    AttributeLDAPDisplayName:
      - gPCMachineExtensionNames
      - gPCUserExtensionNames
    AttributeValue|contains:
      - CAB54552-DEEA-4691-817E-ED4A4D1AFC72
      - AADCED64-746C-4633-A97C-D61349046527
  selection_5145:
    EventID: 5145
    ShareName|endswith: \SYSVOL
    RelativeTargetName|endswith: ScheduledTasks.xml
    AccessList|contains:
      - WriteData
      - "%%4417"
  condition: 1 of selection_*
falsepositives:
  - If the source IP is not localhost then it's super suspicious, better to monitor both local and remote changes to GPO scheduled tasks.
level: high
license: DRL-1.1
related:
  - id: a8f29a7b-b137-4446-80a0-b804272f3da2
    type: derived

What it detects

This rule flags Windows security events indicating GPO modifications that write ScheduledTasks.xml into SYSVOL, enabling scheduled task deployment across machines. Attackers use this mechanism for persistence and lateral execution at scale by distributing task definitions through Group Policy. The detection relies on EventID 5136 and 5145 telemetry for specific GPO extension identifiers and write access patterns to SYSVOL\ScheduledTasks.xml.

Known false positives

  • If the source IP is not localhost then it's super suspicious, better to monitor both local and remote changes to GPO scheduled tasks.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.