Skip to content
Security

Event ID 4698: Scheduled task created

A scheduled task was createdSecurity event 4698 records a new scheduled task with its full XML: command, arguments, run-as account and triggers. A key persistence and remote exec signal.
4698
Event ID
4698
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 4698 means

Event 4698 is written when a scheduled task is registered. Its core is TaskContent, the complete task XML as stored by the Task Scheduler — so a single record tells you what will run (<Exec><Command> and <Arguments>), as whom (<Principals>), when (<Triggers>), and with which settings, plus the account that created it.

Scheduled tasks serve attackers in two ways: persistence (a task that runs a payload at logon, at boot or on a timer) and remote execution (create a task on another host, run it once, delete it — the pattern of schtasks /create /s, Impacket atexec and many ransomware deployments). The second pattern shows up as 4698 followed within seconds by 4699 for the same TaskName.

Built-in tasks under \Microsoft\Windows\ and software updaters (browsers, Office, vendor tools) create and re-create tasks constantly, especially after updates. Baseline those names and focus on what they run.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Other Object Access Events (Success). Not enabled in the default audit policy.

No SACL is needed. Recent Windows builds add ClientProcessId, ParentProcessId, ClientProcessStartKey, RpcCallClientLocality and FQDN to identify the process that made the request. The Task Scheduler Operational log records similar lifecycle events (106, 140, 141) without audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change. For remote task management (schtasks /s, Impacket) this is the remote account.
SubjectDomainNameDomain or computer name of that account.
SubjectLogonIdLogon session of the account; pivot to 4624 on the same host to find where it came from.
TaskNameFull task path, e.g. \Microsoft\Windows\... for built-in tasks. Tasks at the root (\Name) or with names mimicking Microsoft ones deserve a look.
TaskContentThe task's full XML definition. Read Actions/Exec/Command and Arguments (what runs), Principals (UserId, RunLevel — HighestAvailable means elevated), Triggers and Settings/Hidden.
ClientProcessIdPID of the process that requested the change, on builds that log it. Match it to 4688.

Common benign sources

  • Windows servicing and feature updates registering tasks under \Microsoft\Windows\.
  • Browser and application updaters (Google, Edge, Adobe, Office) creating their update tasks.
  • Administrators or GPO preferences deploying maintenance tasks.

What attackers do that produces it

  • Persistence tasks running powershell.exe, cmd.exe, rundll32.exe, mshta.exe or a binary in AppData / ProgramData / C:\Users\Public, often at logon or every few minutes.
  • Remote execution: a task created by a remote account (network logon), run as SYSTEM, then deleted (4699) within seconds.
  • Tasks with Hidden set to true, names imitating Microsoft tasks, or placed at the root of the task library.
  • Ransomware operators pushing a task to many hosts at once via GPO or remote schtasks.

Investigation tips

  • Parse TaskContent and extract Command, Arguments, UserId and RunLevel; review anything not in your baseline of known task names and commands.
  • Look for 4699 with the same TaskName shortly after — create/run/delete is typical of remote execution.
  • Pivot on SubjectLogonId to the 4624 on the same host; a type 3 logon means the task was created remotely and gives the source IP.
  • Confirm execution in Task Scheduler Operational (106, 200, 201) and 4688 children of svchost.exe / taskeng.exe.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideScheduled task persistence: Event ID 4698 and the Task Scheduler log

Sources and further reading