Compliance Node Overview
MITRE ATT&CK T1053.005 (Scheduled Task) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1018 User Account Management, M1047 Audit, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1053/005/
SHA-256 integrity: 0b7fd066d72635a5abdbe26b2b08046225b7aa82672b0e83c7a65718ed78d0df
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1053.005: Scheduled Task (https://attack.mitre.org/techniques/T1053/005/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access