Windows Task Scheduler: SVR Scheduled Task Names (GraphicalProton) Matching
Flags Windows scheduled task creation, update, or deletion when task names match known SVR GraphicalProton backdoor strings.
FreeReviewedSigma · High · v5
- Product
- windows
- Service
- taskscheduler
- Author
- CISA (SigmaHQ), DRL 1.1
- Published
- 2023-12-18
- Updated
- 2026-07-31
What it detects
This rule identifies Windows scheduled task creation, update, or deletion events where the task name matches a list of SVR-specific names. Attackers can use scheduled tasks to establish persistence and run malicious activity under trusted Windows mechanisms. The detection relies on Microsoft-Windows-TaskScheduler Operational telemetry with Task Scheduler EventIDs 129, 140, and 141 and the TaskName field.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-task-scheduler-svr-graphicalproton-known-malicious-scheduled-task-names-2bfc1373
title: "Windows Task Scheduler: SVR Scheduled Task Names (GraphicalProton) Matching"
id: 3793a44f-ea8d-4a99-b8a0-dc68b7acecf3
related:
- id: 8fa65166-f463-4fd2-ad4f-1436133c52e1
type: similar
- id: 2bfc1373-0220-4fbd-8b10-33ddafd2a142
type: derived
status: test
description: This rule identifies Windows scheduled task creation, update, or deletion events where the task name matches a list of SVR-specific names. Attackers can use scheduled tasks to establish persistence and run malicious activity under trusted Windows mechanisms. The detection relies on Microsoft-Windows-TaskScheduler Operational telemetry with Task Scheduler EventIDs 129, 140, and 141 and the TaskName field.
author: CISA, Huntrule Team
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Cozy-Bear/win_taskscheduler_apt_cozy_bear_graphical_proton_task_names.yml
date: 2023-12-18
tags:
- attack.persistence
- detection.emerging-threats
logsource:
product: windows
service: taskscheduler
definition: 'Requirements: The "Microsoft-Windows-TaskScheduler/Operational" is disabled by default and needs to be enabled in order for this detection to trigger'
detection:
selection:
EventID:
- 129
- 140
- 141
TaskName:
- \defender
- \Microsoft\DefenderService
- \Microsoft\Windows\Application Experience\StartupAppTaskCheck
- \Microsoft\Windows\Application Experience\StartupAppTaskCkeck
- \Microsoft\Windows\ATPUpd
- \Microsoft\Windows\Data Integrity Scan\Data Integrity Update
- \Microsoft\Windows\DefenderUPDService
- \Microsoft\Windows\IISUpdateService
- \Microsoft\Windows\Speech\SpeechModelInstallTask
- \Microsoft\Windows\WiMSDFS
- \Microsoft\Windows\Windows Defender\Defender Update Service
- \Microsoft\Windows\Windows Defender\Service Update
- \Microsoft\Windows\Windows Error Reporting\CheckReporting
- \Microsoft\Windows\Windows Error Reporting\SubmitReporting
- \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStart
- \Microsoft\Windows\WindowsDefenderService
- \Microsoft\Windows\WindowsDefenderService2
- \Microsoft\Windows\WindowsUpdate\Scheduled AutoCheck
- \Microsoft\Windows\WindowsUpdate\Scheduled Check
- \WindowUpdate
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1