hunting-for-scheduled-task-persistence skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Workflow
- Key Concepts
- Tools & Systems
- Common Scenarios
- Output Format
- Other files in this skill
- assets/template.md (verbatim)
- Hunt Metadata
- Hypothesis
- Target Techniques
- Data Sources
- Queries Executed
- Query 1: [Description]
- Query 2: [Description]
- Findings
- IOCs Discovered
- Network IOCs
- Host IOCs
- Hunt Results Summary
- Hypothesis Outcome
- Recommendations
- Analyst Notes
- references/api-reference.md (verbatim)
- Libraries Used
- CLI Interface
- Core Functions
- enumeratetasks()
- scaneventlog4698(evtxfile)
- exporttaskxml(taskname)
- Risk Classification
- Dependencies
- references/standards.md (verbatim)
- MITRE ATT&CK Mappings
- Detection Data Sources
- References
- references/workflows.md (verbatim)
- Phase 1: Data Collection and Querying
- Splunk SPL Query
- KQL Query (Microsoft Defender for Endpoint)
- Phase 2: Baseline and Anomaly Detection
- Step 2.1 - Establish Normal Behavior Baseline
- Step 2.2 - Identify Anomalies
- Phase 3: Investigation and Correlation
- Step 3.1 - Deep Dive Analysis
- Step 3.2 - Attack Chain Reconstruction
- Phase 4: Validation and Response
- Step 4.1 - True/False Positive Determination
- Step 4.2 - Response Actions
- Phase 5: Documentation and Reporting
- Step 5.1 - Hunt Report
- Step 5.2 - Knowledge Base Update
What it does. Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual scheduling patterns. Use when hunting for scheduled-task persistence, after threat intel flags related campaigns, during incident response, or when alerts fire on schtasks/at.exe activity. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/hunting-for-scheduled-task-persistence/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill hunting-for-scheduled-task-persistence, or copy the skill folder into~/.claude/skills/hunting-for-scheduled-task-persistence/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/hunting-for-scheduled-task-persistence/SKILL.md
SKILL.md (verbatim)
name: hunting-for-scheduled-task-persistence
description: Runs a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual scheduling patterns. Use when hunting for scheduled-task persistence, after threat intel flags related campaigns, during incident response, or when alerts fire on schtasks/at.exe activity.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- mitre-attack
- scheduled-tasks
- persistence
- t1053
- proactive-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Execution Isolation
- Process Termination
- Hardware-based Process Isolation
- Platform Monitoring
- Process Suspension
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1046
- T1057
- T1082
- T1083
- T1547
Hunting For Scheduled Task Persistence
When to Use
- When proactively hunting for indicators of hunting for scheduled task persistence in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept | Description |
|---|---|
| T1053.005 | Scheduled Task |
| T1053.003 | Cron |
| T1053.002 | At |
Tools & Systems
| Tool | Purpose |
|---|---|
| CrowdStrike Falcon | EDR telemetry and threat detection |
| Microsoft Defender for Endpoint | Advanced hunting with KQL |
| Splunk Enterprise | SIEM log analysis with SPL queries |
| Elastic Security | Detection rules and investigation timeline |
| Sysmon | Detailed Windows event monitoring |
| Velociraptor | Endpoint artifact collection and hunting |
| Sigma Rules | Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Cobalt Strike persistence via schtasks creating periodic beacon
- Scenario 2: Ransomware scheduled task for re-execution after reboot
- Scenario 3: APT encoded PowerShell task running every 30 minutes
- Scenario 4: Insider task to periodically copy sensitive files
Output Format
Hunt ID: TH-HUNTIN-[DATE]-[SEQ]
Technique: T1053.005
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
Other files in this skill
- LICENSE
- assets/template.md
- references/api-reference.md
- references/standards.md
- references/workflows.md
- scripts/agent.py
- scripts/process.py
assets/template.md (verbatim)
Hunting For Scheduled Task Persistence - Hunt Template
Hunt Metadata
| Field | Value |
|---|---|
| Hunt ID | TH-HUNTIN-YYYY-MM-DD-NNN |
| Analyst | |
| Date Started | |
| Date Completed | |
| Status | [ ] In Progress / [ ] Complete |
| Priority | [ ] Critical / [ ] High / [ ] Medium / [ ] Low |
Hypothesis
Statement: [Formulate a clear, testable hypothesis]
Basis: [ ] Threat Intel / [ ] ATT&CK Gap / [ ] Anomaly / [ ] Incident Follow-up
Target Techniques
- T1053.005 - Scheduled Task
- T1053.003 - Cron
- T1053.002 - At
Data Sources
- Sysmon Event Logs
- Windows Security Event Logs
- EDR Telemetry (Platform: _____________)
- SIEM (Platform: _____________)
- Network Logs (Proxy/Firewall/DNS)
- Cloud Audit Logs
- Email Gateway Logs
- Application Logs
Queries Executed
Query 1: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Query 2: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Findings
| # | Timestamp | Host | User | Technique | Evidence Summary | Risk | Verdict |
|---|---|---|---|---|---|---|---|
| 1 | TP / FP / BTP | ||||||
| 2 | TP / FP / BTP | ||||||
| 3 | TP / FP / BTP |
IOCs Discovered
Network IOCs
| Type | Value | Context | Confidence |
|---|---|---|---|
| IP | |||
| Domain | |||
| URL |
Host IOCs
| Type | Value | Context | Confidence |
|---|---|---|---|
| SHA256 | |||
| Filename | |||
| Registry Key | |||
| Scheduled Task |
Hunt Results Summary
| Metric | Count |
|---|---|
| Total Events Analyzed | |
| Anomalies Identified | |
| True Positives | |
| False Positives | |
| Benign True Positives | |
| New IOCs Discovered | |
| Detection Rules Created | |
| Detection Rules Updated |
Hypothesis Outcome
- Confirmed: Evidence supports the hypothesis
- Partially Confirmed: Some evidence found, further investigation needed
- Refuted: No evidence found
- Inconclusive: Insufficient data
Recommendations
- Immediate Actions: [Containment, remediation steps]
- Detection Improvements: [New rules, tuning recommendations]
- Visibility Gaps: [Missing data sources, coverage needs]
- Security Hardening: [Configuration changes, policy updates]
- Follow-up Hunts: [Related hypotheses to investigate]
Analyst Notes
[Free-form notes, observations, and lessons learned]
references/api-reference.md (verbatim)
API Reference — Hunting for Scheduled Task Persistence
Libraries Used
- subprocess: Execute
schtasks /queryandschtasks /query /xmlfor task enumeration - csv: Parse schtasks CSV output for structured task analysis
- python-evtx (Evtx): Parse Security EVTX for Event ID 4698 (Task Created)
CLI Interface
python agent.py enumerate # List and risk-score all tasks
python agent.py events --evtx-file <path> # Scan EVTX for task creation events
python agent.py export --task-name <name> # Export task XML definition
Core Functions
enumerate_tasks()
Runs schtasks /query /fo CSV /v and classifies each task as high/medium/low risk.
Returns: dict with total_tasks, high_risk, medium_risk, suspicious_tasks, non_vendor_tasks.
scan_event_log_4698(evtx_file)
Parses Windows Security EVTX for Event ID 4698 (Scheduled Task Created).
Parameters:
| Name | Type | Description |
|---|---|---|
evtx_file |
str | Path to Security .evtx log file |
export_task_xml(task_name)
Exports a task's full XML definition using schtasks /query /tn <name> /xml.
Risk Classification
| Risk | Criteria |
|---|---|
| High | Action matches suspicious patterns (powershell -enc, certutil, temp paths) |
| Medium | Non-vendor task (not under \Microsoft\, \Google\, etc.) |
| Low | Known vendor task prefix |
Dependencies
pip install python-evtx # Optional, for EVTX parsing
references/standards.md (verbatim)
Standards and References - Hunting For Scheduled Task Persistence
MITRE ATT&CK Mappings
| Technique | Name | Description |
|---|---|---|
| T1053.005 | Scheduled Task | See attack.mitre.org/techniques/T1053/005 |
| T1053.003 | Cron | See attack.mitre.org/techniques/T1053/003 |
| T1053.002 | At | See attack.mitre.org/techniques/T1053/002 |
Detection Data Sources
| Source | Event ID | Purpose |
|---|---|---|
| Sysmon | 1 | Process creation with command line |
| Sysmon | 3 | Network connection initiated |
| Sysmon | 7 | Image loaded (DLL) |
| Sysmon | 10 | Process access (LSASS) |
| Sysmon | 11 | File creation |
| Sysmon | 12/13 | Registry create/set |
| Sysmon | 22 | DNS query |
| Sysmon | 25 | Process tampering |
| Windows Security | 4624 | Successful logon |
| Windows Security | 4625 | Failed logon |
| Windows Security | 4648 | Explicit credential logon |
| Windows Security | 4672 | Special privileges assigned |
| Windows Security | 4688 | Process creation |
| Windows Security | 4697 | Service installed |
| Windows Security | 4698 | Scheduled task created |
| Windows Security | 4769 | Kerberos TGS requested |
| Windows Security | 5140 | Network share accessed |
References
- MITRE ATT&CK Framework: https://attack.mitre.org/
- Sigma Detection Rules: https://github.com/SigmaHQ/sigma
- LOLBAS Project: https://lolbas-project.github.io/
- Atomic Red Team Tests: https://github.com/redcanaryco/atomic-red-team
- Red Canary Threat Detection Report
- SANS Threat Hunting Summit Resources
references/workflows.md (verbatim)
Detailed Hunting Workflow - Hunting For Scheduled Task Persistence
Phase 1: Data Collection and Querying
Splunk SPL Query
index=wineventlog (EventCode=4698 OR EventCode=106)
| where match(Task_Content, "(?i)(powershell|cmd|wscript|mshta|http|encoded)")
| table _time Computer User Task_Name Task_Content
KQL Query (Microsoft Defender for Endpoint)
DeviceEvents
| where ActionType == "ScheduledTaskCreated"
| where AdditionalFields has_any ("powershell","cmd","wscript","http")
| project Timestamp, DeviceName, AccountName, AdditionalFields
Phase 2: Baseline and Anomaly Detection
Step 2.1 - Establish Normal Behavior Baseline
- Collect 30 days of historical data for the targeted technique
- Document expected patterns, frequencies, and legitimate use cases
- Identify known false positive sources and document exceptions
- Build statistical baseline (mean, standard deviation) for key metrics
Step 2.2 - Identify Anomalies
- Compare current activity against the 30-day baseline
- Flag events exceeding 3 standard deviations from normal
- Prioritize anomalies by risk score and potential business impact
- Cross-reference with threat intelligence for known IOCs
Phase 3: Investigation and Correlation
Step 3.1 - Deep Dive Analysis
- For each anomaly, collect full process tree context
- Correlate with network activity, file operations, and authentication events
- Check binary signatures, file hashes, and certificate validity
- Review user account context and access patterns
Step 3.2 - Attack Chain Reconstruction
- Map findings to MITRE ATT&CK kill chain stages
- Identify initial access vector if applicable
- Trace lateral movement and privilege escalation paths
- Determine data access and potential exfiltration
Phase 4: Validation and Response
Step 4.1 - True/False Positive Determination
- Verify findings with system owners and IT operations
- Check change management records for authorized activities
- Validate user context (authorized actions vs. compromised account)
- Document determination rationale for each finding
Step 4.2 - Response Actions
- For confirmed threats: initiate incident response procedures
- For detection gaps: create or update detection rules
- For false positives: tune existing rules and update exclusions
- Update threat hunting playbook with lessons learned
Phase 5: Documentation and Reporting
Step 5.1 - Hunt Report
- Summarize hypothesis, methodology, and findings
- Include all queries executed and their results
- Document IOCs discovered and detection rules created
- Provide recommendations for security improvements
Step 5.2 - Knowledge Base Update
- Add findings to threat intelligence platform
- Update MITRE ATT&CK coverage heatmap
- Share detection rules via Sigma format
- Schedule follow-up hunts for related techniques
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.