Suspicious Task Scheduler XML Pattern Related with AtExec

Rule Info

Name
Suspicious Task Scheduler XML Pattern Related with AtExec
Author
Swachchhanda Shrawn Poudel (Nextron Systems)
Description
Detects creation of scheduled tasks with XML patterns commonly associated with Atexec, a component of the NetExec tool that allows execution of commands via scheduled tasks for persistence and privilege escalation.
Date
2026-04-27 00:00:00
Modified
None
Id
2c359eb1-1a3b-4856-8522-df649f2c1c62
Tags
attack.execution attack.persistence attack.privilege-escalation attack.t1053.005
Type
Nextron Sigma feed only (private)

Rule History