Windows Security: Scheduled Task Persistence via 4698 for "SC Scheduled Scan" and "UpdatMachine"

Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".

FreeUnreviewedSigmacriticalv1
title: 'Windows Security: Scheduled Task Persistence via 4698 for "SC Scheduled Scan" and "UpdatMachine"'
id: 9919620f-540a-4d89-a6b7-19e3057c00cd
related:
  - id: 53ba33fd-3a50-4468-a5ef-c583635cfa92
    type: similar
  - id: 7bdf2a7c-3acc-4091-9581-0a77dad1c5b5
    type: similar
  - id: ce6e34ca-966d-41c9-8d93-5b06c8b97a06
    type: similar
  - id: c0580559-a6bd-4ef6-b9b7-83703d98b561
    type: derived
status: test
description: This rule flags Windows Security events (Event ID 4698) where a new scheduled task is created with the task name "SC Scheduled Scan" or "UpdatMachine". Creating scheduled tasks is a common persistence technique that can help an attacker repeatedly execute code across reboots. It relies on Windows Security audit telemetry for task creation events and matches on the task name field.
references:
  - https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2018/TA/OilRig/win_security_apt_oilrig_mar18.yml
author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule Team
date: 2018-03-23
modified: 2023-03-08
tags:
  - attack.privilege-escalation
  - attack.execution
  - attack.persistence
  - attack.defense-impairment
  - attack.g0049
  - attack.t1053.005
  - attack.s0111
  - attack.t1543.003
  - attack.t1112
  - attack.command-and-control
  - attack.t1071.004
  - detection.emerging-threats
logsource:
  product: windows
  service: security
detection:
  selection_service:
    EventID: 4698
    TaskName:
      - SC Scheduled Scan
      - UpdatMachine
  condition: selection_service
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1

What it detects

This rule flags Windows Security events (Event ID 4698) where a new scheduled task is created with the task name "SC Scheduled Scan" or "UpdatMachine". Creating scheduled tasks is a common persistence technique that can help an attacker repeatedly execute code across reboots. It relies on Windows Security audit telemetry for task creation events and matches on the task name field.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.