The Detection Gap: MITRE ATT&CK T1053.005
Symantec, Thursday, August 6th, 2026
Symantec's Detection Gap series examines MITRE ATT&CK T1053.005 scheduled task abuse.
This entry in Symantec's Detection Gap series examines MITRE ATT&CK technique T1053.005, covering scheduled task and job abuse.
Attackers use Windows scheduled tasks for persistence because the activity blends with legitimate administrative work.
The post contrasts benign task creation, which follows proper change management and uses known accounts, with malicious variants.
That contrast is what makes detection tractable without overwhelming analysts with false positives.