Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence

Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".

FreeReviewedSigma · Critical · v5
Product
windows
Service
security
Author
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2018-03-23
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. Exfiltration

  10. Impact

What it detects

This rule flags Windows Security event 4698 entries that create scheduled tasks named “SC Scheduled Scan” or “UpdatMachine.” Attackers can use scheduled tasks to persist execution across reboots while blending into normal Windows job activity. It relies on telemetry from the Windows Security log capturing scheduled task creation events and the task name field.

Related detections9 linkedT1112 — drag to rearrange
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Windows Registry Persistence via UMe/UT Run Keys
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Hidden Scheduled Task via TaskCache Security Descriptor Manipulation
Suspicious Windows Service Trigger Configuration via Registry Modification
Suspicious Service Persistence Masquerading as DevQueryBrokerService
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Pivot detection · T1112 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.