| name | hunting-for-scheduled-task-persistence |
| description | Hunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns. Use when hunting for adversary persistence via windows scheduled tasks by analyzing. |
| domain | cybersecurity |
| tags | ["threat-hunting","mitre-attack","scheduled-tasks","persistence","t1053","proactive-detection"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["Execution Isolation","Process Termination","Hardware-based Process Isolation","Platform Monitoring","Process Suspension"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Scheduled Task Persistence
Overview
Cybersecurity skill for hunting for scheduled task persistence. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for scheduled task persistence"
-
"When proactively hunting for indicators of hunting for scheduled task persistenc"
-
"After threat intelligence indicates active campaigns using these techniques"
-
"During incident response to scope compromise related to these techniques"
-
When proactively hunting for indicators of hunting for scheduled task persistence in the environment
-
After threat intelligence indicates active campaigns using these techniques
-
During incident response to scope compromise related to these techniques
-
When EDR or SIEM alerts trigger on related indicators
-
During periodic security assessments and purple team exercises
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}