T1053.005Scheduled Task
T1053.005 — Scheduled Task is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 51 detection use cases covering it and 25 threat-intel articles citing it.
ExecutionPersistencePrivilege Escalation
51Use cases
25Articles
0Sub-techniques
3Tactics
↑ Parent technique: T1053 · Scheduled Task/Job
Use cases covering this technique (51)
Scheduled task created with suspicious image / encoded args Possible Lateral Movement PowerShell Spawn Randomly Generated Scheduled Task Name Scheduled Task Deleted Or Created via CMD Scheduled Task Initiation on Remote Endpoint Schtasks scheduling job on remote system Schtasks used for forcing a reboot Short Lived Scheduled Task Suspicious Scheduled Task from Public Directory Svchost LOLBAS Execution Process Spawn Windows Compatibility Telemetry Suspicious Child Process Windows Compatibility Telemetry Tampering Through Registry Windows Enable Win32 ScheduledJob via Registry Windows PowerShell ScheduleTask Windows Registry Delete Task SD Windows Scheduled Task Created in a Group Policy Object Windows Scheduled Task Created Via XML Windows Scheduled Task Service Spawned Shell Windows Scheduled Task with Highest Privileges Windows Scheduled Task with Suspicious Command Windows Scheduled Task with Suspicious Name Windows Schtasks Create Run As System WinEvent Scheduled Task Created to Spawn Shell WinEvent Scheduled Task Created Within Public Path WinEvent Windows Task Scheduler Event Action Started Scheduled tasks used in BadRabbit ransomware Article-specific behavioural hunt — Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth Article-specific behavioural hunt — APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Window Article-specific behavioural hunt — APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Window [LLM] CoolClient persistence: schtasks onstart SYSTEM task masquerading as 'Windows Defender ATP Service' running defender.exe Article-specific behavioural hunt — China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud [LLM] Flowise node process writes to cron / systemd / SSH persistence path Article-specific behavioural hunt — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware deliver Article-specific behavioural hunt — OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage cam Article-specific behavioural hunt — OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage cam [LLM] OctLurk deployment via 'GoogleUpDate' scheduled task launching Videos\1.bat Article-specific behavioural hunt — IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack Article-specific behavioural hunt — Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Article-specific behavioural hunt — Begun, the Patch Wars have Article-specific behavioural hunt — UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially Article-specific behavioural hunt — Webworm: New burrowing techniques Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans [LLM] PicassoLoader scheduled-task creation by wscript/cscript after C2 XML fetch Article-specific behavioural hunt — DynoWiper update: Technical analysis and attribution Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder [LLM] MuddyViper persistence via ManageOnDriveUpdater scheduled task or Startup folder hijack [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk Article-specific behavioural hunt — Setting up SSL/TLS for Kubernetes IngressArticles citing this technique (25)
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit Begun, the Patch Wars have art-253
crit CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability art-1184
crit Breaking out of message brokers art-3345