Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".
FreeReviewedSigma · Critical · v5
- Product
- windows
- Service
- security
- Author
- Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2018-03-23
- Updated
- 2026-07-31
ATT&CK techniques
Execution → C2Recon
Resource Dev
Initial Access
Execution
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags Windows Security event 4698 entries that create scheduled tasks named “SC Scheduled Scan” or “UpdatMachine.” Attackers can use scheduled tasks to persist execution across reboots while blending into normal Windows job activity. It relies on telemetry from the Windows Security log capturing scheduled task creation events and the task name field.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-security-scheduled-task-persistence-via-4698-for-sc-scheduled-scan-and-u-c0580559
title: "Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence"
id: 9919620f-540a-4d89-a6b7-19e3057c00cd
related:
- id: 53ba33fd-3a50-4468-a5ef-c583635cfa92
type: similar
- id: 7bdf2a7c-3acc-4091-9581-0a77dad1c5b5
type: similar
- id: ce6e34ca-966d-41c9-8d93-5b06c8b97a06
type: similar
- id: c0580559-a6bd-4ef6-b9b7-83703d98b561
type: derived
status: test
description: This rule flags Windows Security event 4698 entries that create scheduled tasks named “SC Scheduled Scan” or “UpdatMachine.” Attackers can use scheduled tasks to persist execution across reboots while blending into normal Windows job activity. It relies on telemetry from the Windows Security log capturing scheduled task creation events and the task name field.
references:
- https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2018/TA/OilRig/win_security_apt_oilrig_mar18.yml
author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule Team
date: 2018-03-23
modified: 2023-03-08
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.defense-impairment
- attack.g0049
- attack.t1053.005
- attack.s0111
- attack.t1543.003
- attack.t1112
- attack.command-and-control
- attack.t1071.004
- detection.emerging-threats
logsource:
product: windows
service: security
detection:
selection_service:
EventID: 4698
TaskName:
- SC Scheduled Scan
- UpdatMachine
condition: selection_service
falsepositives:
- Unlikely
level: critical
license: DRL-1.1