Potential BearLPE Exploitation via Windows Task Scheduler schtasks.exe DACL Change

Flags schtasks.exe executions with /change, /TN, /RU, and /RP, consistent with task modification tied to BearLPE attempts.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Olaf Hartong (SigmaHQ), DRL 1.1
Published
2019-05-22
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows process creation where schtasks.exe is invoked with command-line arguments that indicate changing a scheduled task and configuring it to run as a specified user with a specified password. The combination of /change, /TN, /RU, and /RP is used to modify task settings in a way that can be leveraged for privilege escalation attempts consistent with BearLPE exploitation activity. Telemetry required is Windows process creation events including the process image name and full command line.

Related detections9 linkedT1053.005 — drag to rearrange
Suspicious Scheduled Task Named WindowsHelper (via process_creation)
Scheduled Task Masquerading as Microsoft Wininet Config
Suspicious SYSTEM Scheduled Task Named test Created via schtasks
Suspicious Scheduled Task Created by Windows Script Host
Malicious CloudZ RAT Persistence via schtasks Running regasm.exe
Suspicious Scheduled Task Creation for WSPrint Persistence by UAT-9244
Malicious Scheduled Task Masquerading as GoogleUpdate Launching SSH Reverse Shell
Malicious Scheduled Task Creation TaskSystem via Interlock Ransomware
Malicious Scheduled Task Masquerading as Edge Update Running From Temp (via process_creation)
Potential BearLPE Exploitation via Windows Task Scheduler schtasks.exe DACL Change
Pivot detection · T1053.005 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.