Skip to content
Threat Feed
low advisory

Detection of Unauthorized Scheduled Task Modifications

This detection brief identifies potential persistence mechanisms where non-system users modify Windows scheduled tasks to execute malicious code.

Adversaries frequently leverage the Windows Task Scheduler to maintain persistence by modifying existing tasks to execute malicious binaries or scripts. While scheduled tasks are essential for system automation, unauthorized modifications by non-system user accounts are often indicative of malicious activity.

This brief focuses on the detection of event ID 4702, which records when a scheduled task is updated. By filtering out system and machine accounts (S-1-5-18, S-1-5-19, S-1-5-20), defenders can isolate modifications performed by standard or administrative user accounts. This approach helps in identifying anomalous task updates that may deviate from baseline administrative behavior. Defenders should prioritize investigating modifications that involve suspicious script paths or infrequent task names to distinguish between routine maintenance and potential persistence attempts.

Impact

Successful abuse of scheduled tasks allows attackers to achieve long-term persistence on compromised endpoints, enabling them to execute malicious payloads automatically at system startup, user login, or specific time intervals. This technique facilitates further stages of an attack, such as credential harvesting, lateral movement, or data exfiltration.

Recommendation

Prioritize the implementation of the following detection logic to monitor for unauthorized modifications.

  • Enable "Audit Other Object Access" events in Windows Group Policy to ensure Event ID 4702 is captured.
  • Deploy the provided Sigma rule to your SIEM environment to monitor for task updates by non-system accounts.
  • Maintain a baseline of legitimate scheduled task modifications associated with software deployment tools and administrative maintenance to reduce false positive noise.
  • Investigate triggered alerts by cross-referencing the modified task command or script path with known-good organizational baselines.

Immediate actions

Enable Audit Other Object Access events across the domain.

IT Operations 72h

Threat Hunt

Search for Event ID 4702 occurrences involving non-system accounts.

T1053.005 medium medium confidence convert to detection

Data: Windows Security Event Logs

Mitigations

Review all existing scheduled tasks for unauthorized changes.

short_term SOC

T1053.005

Detection coverage 1

Detect Unusual Scheduled Task Update

low

Detects the first-time modification of a scheduled task by a non-system user account, which may indicate persistence activity.

sigma tactics: persistence techniques: T1053.005 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →