T1053.005Scheduled Task
T1053.005 — Scheduled Task is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 61 detection use cases covering it and 28 threat-intel articles citing it.
ExecutionPersistencePrivilege Escalation
61Use cases
28Articles
0Sub-techniques
3Tactics
↑ Parent technique: T1053 · Scheduled Task/Job
Use cases covering this technique (61)
Scheduled task created with suspicious image / encoded args Possible Lateral Movement PowerShell Spawn Randomly Generated Scheduled Task Name Scheduled Task Deleted Or Created via CMD Scheduled Task Initiation on Remote Endpoint Schtasks scheduling job on remote system Schtasks used for forcing a reboot Short Lived Scheduled Task Suspicious Scheduled Task from Public Directory Svchost LOLBAS Execution Process Spawn Windows Compatibility Telemetry Suspicious Child Process Windows Compatibility Telemetry Tampering Through Registry Windows Enable Win32 ScheduledJob via Registry Windows PowerShell ScheduleTask Windows Registry Delete Task SD Windows Scheduled Task Created in a Group Policy Object Windows Scheduled Task Created Via XML Windows Scheduled Task Service Spawned Shell Windows Scheduled Task with Highest Privileges Windows Scheduled Task with Suspicious Command Windows Scheduled Task with Suspicious Name Windows Schtasks Create Run As System WinEvent Scheduled Task Created to Spawn Shell WinEvent Scheduled Task Created Within Public Path WinEvent Windows Task Scheduler Event Action Started Scheduled tasks used in BadRabbit ransomware Article-specific behavioural hunt — IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack Article-specific behavioural hunt — TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments Article-specific behavioural hunt — Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Article-specific behavioural hunt — ACR Stealer: Two observed intrusion chains amid increased threat activity Article-specific behavioural hunt — ACR Stealer: Two observed intrusion chains amid increased threat activity [LLM] Masqueraded 'Autoupdate' scheduled task run by PowerShell loader (ACR Stealer persistence) Article-specific behavioural hunt — Begun, the Patch Wars have Article-specific behavioural hunt — UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially Article-specific behavioural hunt — OkoBot: new sophisticated malware framework targets cryptocurrency users [LLM] OkoBot 'Apple Sync' scheduled task maintaining reverse SSH tunnel forwarding RDP Article-specific behavioural hunt — No Manners Here: The Ruthless Rise of The Gentlemen Ransomware [LLM] The Gentlemen ransomware scheduled task named gentlemen* Article-specific behavioural hunt — Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation Article-specific behavioural hunt — Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation Article-specific behavioural hunt — Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign Article-specific behavioural hunt — Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign [LLM] BusySnake VBScript persistence: wh_selfdelete.vbs / run.vbs in WindowsHelper Article-specific behavioural hunt — Missed incidents, persistent threats, and response gaps: Insights from compromis Article-specific behavioural hunt — CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Article-specific behavioural hunt — CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure [LLM] Scheduled task persistence for GoogleUpdater or VMware-disguised VNT binary Article-specific behavioural hunt — Webworm: New burrowing techniques Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans [LLM] PicassoLoader scheduled-task creation by wscript/cscript after C2 XML fetch Article-specific behavioural hunt — GlassWorm Hides a RAT Inside a Malicious Chrome Extension Article-specific behavioural hunt — Glassworm Strikes Popular React Native Phone Number Packages [LLM] Glassworm stage-3 persistence: schtasks UpdateApp + HKCU Run DPKCbbQ Article-specific behavioural hunt — DynoWiper update: Technical analysis and attribution Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder [LLM] MuddyViper persistence via ManageOnDriveUpdater scheduled task or Startup folder hijack [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk Article-specific behavioural hunt — Setting up SSL/TLS for Kubernetes IngressArticles citing this technique (28)
crit Begun, the Patch Wars have art-150
crit CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability art-1161
crit Breaking out of message brokers art-3322