Event ID 4702: Scheduled task updated
- Event ID
- 4702
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 4702 means
Event 4702 is written when an existing scheduled task is modified. The new definition is in TaskContentNew; the previous version is not included, so you need an earlier 4698 or 4702 (or a baseline) to see what changed.
Modifying an existing task is stealthier than creating one: the task name stays familiar, and only the action, arguments, account or trigger change. Watch for built-in or vendor tasks whose Command suddenly points to a script host or a user-writable path, or whose RunLevel becomes HighestAvailable.
Expect a lot of benign volume: Windows and application updaters rewrite their tasks regularly, frequently as SYSTEM or the machine account.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Other Object Access Events (Success). Not enabled in the default audit policy.
No SACL is needed. Recent Windows builds add ClientProcessId, ParentProcessId, ClientProcessStartKey, RpcCallClientLocality and FQDN to identify the process that made the request. The Task Scheduler Operational log records similar lifecycle events (106, 140, 141) without audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change. For remote task management (schtasks /s, Impacket) this is the remote account. |
| SubjectDomainName | Domain or computer name of that account. |
| SubjectLogonId | Logon session of the account; pivot to 4624 on the same host to find where it came from. |
| TaskName | Full task path, e.g. \Microsoft\Windows\... for built-in tasks. Tasks at the root (\Name) or with names mimicking Microsoft ones deserve a look. |
| TaskContentNew | The task's new XML definition. Compare Actions/Exec/Command, Arguments, Principals and Triggers with the previous version. |
| ClientProcessId | PID of the process that requested the change, on builds that log it. Match it to 4688. |
Common benign sources
- Windows servicing and application updaters rewriting their tasks, often after each update.
- Group Policy preferences refreshing managed tasks.
What attackers do that produces it
- Hijacking an existing task by changing its action to run a payload, keeping the trusted task name.
- Changing a task's principal to SYSTEM or its RunLevel to
HighestAvailableto gain elevated execution.
Investigation tips
- Compare TaskContentNew with the last known definition (earlier 4698/4702, exported task XML from
C:\Windows\System32\Tasks) and focus on changes to Command and Arguments. - Filter out known updater tasks, then review updates made by interactive or remote user sessions.
- Confirm when the modified task next ran via Task Scheduler Operational 200/201 and 4688.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighSuspicious Scheduled Task UpdateRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.