CG
SkillsDetecting Malicious Scheduled Tasks with Sysmon
Start Free
Back to Skills Library
Threat Hunting🟡 Intermediate

Detecting Malicious Scheduled Tasks with Sysmon

Detect malicious scheduled task creation and modification using Sysmon Event IDs 1 (Process Create for schtasks.exe), 11 (File Create for task XML), and Windows Security Event 4698/4702.

3 min read1 code examples1 MITRE techniques

Prerequisites

  • Sysmon installed with a detection-focused configuration (e.g., SwiftOnSecurity or Olaf Hartong)
  • Windows Event Log forwarding to SIEM (Splunk, Elastic, or Sentinel)
  • PowerShell ScriptBlock Logging enabled (Event 4104)

MITRE ATT&CK Coverage

T1053.005

Detecting Malicious Scheduled Tasks with Sysmon

Overview

Adversaries abuse Windows Task Scheduler (schtasks.exe, at.exe) for persistence (T1053.005)

and lateral movement. Sysmon Event ID 1 captures schtasks.exe process creation with full

command-line arguments, while Event ID 11 captures task XML files written to

C:\Windows\System32\Tasks\. Windows Security Event 4698 logs task registration details.

This guide covers building detection rules that correlate these events to identify

malicious scheduled tasks created from suspicious paths, with encoded payloads, or

targeting remote systems.

Prerequisites

  • Sysmon installed with a detection-focused configuration (e.g., SwiftOnSecurity or Olaf Hartong)
  • Windows Event Log forwarding to SIEM (Splunk, Elastic, or Sentinel)
  • PowerShell ScriptBlock Logging enabled (Event 4104)

Steps

  1. Configure Sysmon to log Event IDs 1, 11, 12, 13 with task-related filters
  2. Build detection rules for schtasks.exe /create with suspicious arguments
  3. Correlate Event 4698 (task registered) with Sysmon Event 1 (process create)
  4. Hunt for tasks executing from public directories or with encoded commands
  5. Alert on remote task creation (schtasks /s) for lateral movement detection

Expected Output

[CRITICAL] Suspicious Scheduled Task Detected
  Task: \Microsoft\Windows\UpdateCheck
  Command: powershell.exe -enc SQBuAHYAbwBrAGUALQBXAGUAYgBSAGU...
  Created By: DOMAIN\compromised_user
  Parent Process: cmd.exe (PID 4532)
  Source: \\192.168.1.50 (remote creation)
  MITRE: T1053.005 - Scheduled Task/Job

Verification Criteria

Confirm successful execution by validating:

  • [ ] All prerequisite tools and access requirements are satisfied
  • [ ] Each workflow step completed without errors
  • [ ] Output matches expected format and contains expected data
  • [ ] No security warnings or misconfigurations detected
  • [ ] Results are documented and evidence is preserved for audit

Compliance Framework Mapping

This skill supports compliance evidence collection across multiple frameworks:

  • SOC 2: CC7.2 (Anomaly Detection), CC7.3 (Incident Identification)
  • ISO 27001: A.12.4 (Logging & Monitoring), A.16.1 (Security Incident Management)
  • NIST 800-53: SI-4 (System Monitoring), IR-4 (Incident Handling), RA-5 (Vulnerability Scanning)
  • NIST CSF: DE.AE (Anomalies & Events), DE.CM (Continuous Monitoring), DE.DP (Detection Processes)

Claw GRC Tip: When this skill is executed by a registered agent, compliance evidence is automatically captured and mapped to the relevant controls in your active frameworks.

Deploying This Skill with Claw GRC

Agent Execution

Register this skill with your Claw GRC agent for automated execution:

# Install via CLI
npx claw-grc skills add detecting-malicious-scheduled-tasks-with-sysmon

# Or load dynamically via MCP
grc.load_skill("detecting-malicious-scheduled-tasks-with-sysmon")

Audit Trail Integration

When executed through Claw GRC, every step of this skill generates tamper-evident audit records:

  • SHA-256 chain hashing ensures no step can be modified after execution
  • Evidence artifacts (configs, scan results, logs) are automatically attached to relevant controls
  • Trust score impact — successful execution increases your agent's trust score

Continuous Compliance

Schedule this skill for recurring execution to maintain continuous compliance posture. Claw GRC monitors for drift and alerts when re-execution is needed.

Use with Claw GRC Agents

This skill is fully compatible with Claw GRC's autonomous agent system. Deploy it to any registered agent via MCP, and every execution will be logged in the tamper-evident audit trail.

// Load this skill in your agent
npx claw-grc skills add detecting-malicious-scheduled-tasks-with-sysmon
// Or via MCP
grc.load_skill("detecting-malicious-scheduled-tasks-with-sysmon")

Tags

sysmonscheduled-taskspersistencedetectionthreat-huntingwindows-security

Related Skills

Threat Hunting

Detecting Wmi Persistence

3m·intermediate
Threat Hunting

Hunting for Registry Run Key Persistence

3m·intermediate
Threat Hunting

Hunting for Scheduled Task Persistence

3m·intermediate
Threat Hunting

Hunting for Suspicious Scheduled Tasks

3m·intermediate
Threat Hunting

Detecting Email Forwarding Rules Attack

3m·intermediate
Threat Hunting

Detecting T1055 Process Injection with Sysmon

4m·intermediate

Skill Details

Domain
Threat Hunting
Difficulty
intermediate
Read Time
3 min
Code Examples
1
MITRE IDs
1

On This Page

OverviewPrerequisitesStepsExpected OutputVerification CriteriaCompliance Framework MappingDeploying This Skill with Claw GRC

Deploy This Skill

Add this skill to your Claw GRC agent and start automating.

Get Started Free →