Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Hunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.
When proactively hunting for persistence mechanisms in Windows environments
After detecting schtasks.exe or at.exe usage in process creation logs
When investigating malware that survives reboots and user logoffs
During incident response to enumerate all persistence on compromised systems
When Windows Security Event ID 4698 (Scheduled Task Created) fires for unusual tasks
Detection Gaps & Validation
Audit gap, not "no activity": Security EID 4698/4702 only log when "Object Access > Other Object Access Events" auditing is enabled (default OFF) — absence of 4698 does NOT mean no tasks. Corroborate with Microsoft-Windows-TaskScheduler/Operational (EID 106/140/200) and the registry HKLM\...\Schedule\TaskCache\Tree.
Action-type evasion: tasks whose action is a ComHandler CLSID, and tasks created by writing directly to TaskCache, bypass schtasks.exe EID 1 command-line hunting.
SD-deletion hiding: removing the task's SD makes it vanish from schtasks /query and the GUI while it still executes — diff TaskCache\Tree GUIDs against \Tasks to surface orphans.
Renamed binary: match EID 1 OriginalFileName + CommandLine, since a renamed schtasks.exe defeats Image-name rules.
Validate: run Atomic T1053.005 schtasks and Register-ScheduledTask; confirm 4698 + a new TaskCache registry entry both appear.
FP tuning: baseline \Microsoft\Windows\ built-ins and vendor updater tasks by author/signer.
Prerequisites
Windows Security Event ID 4698/4699/4702 (Task Created/Deleted/Updated)
Sysmon Event ID 1 for schtasks.exe process creation with command lines
Windows Task Scheduler operational log (Microsoft-Windows-TaskScheduler/Operational)
PowerShell logging for Register-ScheduledTask cmdlet usage
Access to Task Scheduler XML definitions on endpoints
Workflow
Enumerate All Scheduled Tasks: Collect complete task inventory from target systems using schtasks /query /fo CSV /v or Get-ScheduledTask PowerShell cmdlet.
Monitor Task Creation Events: Track Event ID 4698 for new task creation, correlating with the creating process and user account context.
Analyze Task Actions: Examine what each task executes. Flag tasks running scripts (PowerShell, cmd, wscript), binaries from user-writable paths (TEMP, AppData, Downloads), or encoded/obfuscated commands.
Check Task Triggers: Review trigger conditions. Tasks triggered by system startup, user logon, or short intervals (1-5 minutes) warrant investigation.
Identify Hidden or Disguised Tasks: Hunt for tasks with names mimicking legitimate Windows tasks, tasks with Security Descriptor modifications hiding them from standard enumeration, or tasks stored in non-standard registry locations.
Correlate with Process Execution: Match scheduled task execution events with process creation logs to confirm what actually runs.
Baseline and Diff: Compare current task inventory against known-good baselines to identify new, modified, or unexpected tasks.
Cobalt Strike Persistence: Creates scheduled tasks via schtasks.exe to execute PowerShell download cradles at user logon intervals.
Ransomware Staging: Task created to run encryption payload at a future time, often during off-hours for maximum impact.
Hidden Task via SD Modification: Attacker modifies Security Descriptor of scheduled task to hide it from normal enumeration while maintaining execution.
COM Handler Abuse: Task uses COM handler rather than direct executable path, making action inspection more complex.
Lateral Movement via Tasks: Remote scheduled task creation using schtasks /create /s REMOTE_HOST for execution on other systems.