Windows Security: Scheduled Task Persistence via 4698 for "SC Scheduled Scan" and "UpdatMachine"
Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".
FreeUnreviewedSigmacriticalv1
windows-security-scheduled-task-persistence-via-4698-for-sc-scheduled-scan-and-u-c0580559
title: 'Windows Security: Scheduled Task Persistence via 4698 for "SC Scheduled Scan" and "UpdatMachine"'
id: 9919620f-540a-4d89-a6b7-19e3057c00cd
related:
- id: 53ba33fd-3a50-4468-a5ef-c583635cfa92
type: similar
- id: 7bdf2a7c-3acc-4091-9581-0a77dad1c5b5
type: similar
- id: ce6e34ca-966d-41c9-8d93-5b06c8b97a06
type: similar
- id: c0580559-a6bd-4ef6-b9b7-83703d98b561
type: derived
status: test
description: This rule flags Windows Security events (Event ID 4698) where a new scheduled task is created with the task name "SC Scheduled Scan" or "UpdatMachine". Creating scheduled tasks is a common persistence technique that can help an attacker repeatedly execute code across reboots. It relies on Windows Security audit telemetry for task creation events and matches on the task name field.
references:
- https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2018/TA/OilRig/win_security_apt_oilrig_mar18.yml
author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule Team
date: 2018-03-23
modified: 2023-03-08
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.defense-impairment
- attack.g0049
- attack.t1053.005
- attack.s0111
- attack.t1543.003
- attack.t1112
- attack.command-and-control
- attack.t1071.004
- detection.emerging-threats
logsource:
product: windows
service: security
detection:
selection_service:
EventID: 4698
TaskName:
- SC Scheduled Scan
- UpdatMachine
condition: selection_service
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
What it detects
This rule flags Windows Security events (Event ID 4698) where a new scheduled task is created with the task name "SC Scheduled Scan" or "UpdatMachine". Creating scheduled tasks is a common persistence technique that can help an attacker repeatedly execute code across reboots. It relies on Windows Security audit telemetry for task creation events and matches on the task name field.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.