Windows Security Event 4698: Kapeka-like Scheduled Task Creation
Flags suspicious Kapeka-like scheduled task creation via Event 4698 using TaskContent paths, rundll32/.wll command markers, and OneDrive/Sens Api task names.
- Product
- windows
- Service
- security
- Author
- Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
- Published
- 2024-07-03
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows scheduled task creation events (EventID 4698) whose task content includes specific file and command-line artifacts consistent with the Kapeka backdoor behavior. It matters because creating scheduled tasks is a common persistence technique and can be used to execute malicious payloads at recurring intervals or system events. The detection relies on Security log telemetry for TaskContent fields, including paths, rundll32/.wll/#1 command fragments, and task names such as “OneDrive” or “Sens Api”.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4698
- labs.withsecure.comhttps://labs.withsecure.com/publications/kapeka
- app.any.runhttps://app.any.run/tasks/1efb3ed4-cc0f-4690-a0ed-24516809bc72/
- virustotal.comhttps://www.virustotal.com/gui/file/bd07fb1e9b4768e7202de6cc454c78c6891270af02085c51fce5539db1386c3f/behavior
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2024/Malware/kapeka/win_security_malware_kapeka_backdoor_scheduled_task_creation.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Security Event 4698: Kapeka-like Scheduled Task Creation"
id: 0c6ec1ff-12ba-4d7b-ba14-952719000e82
related:
- id: 64a871dd-83f6-4e5f-80fc-5a7ca3a8a819
type: similar
- id: 6c130acd-0adb-4545-bcc4-2e85d0883c9a
type: derived
status: test
description: This rule flags Windows scheduled task creation events (EventID 4698) whose task content includes specific file and command-line artifacts consistent with the Kapeka backdoor behavior. It matters because creating scheduled tasks is a common persistence technique and can be used to execute malicious payloads at recurring intervals or system events. The detection relies on Security log telemetry for TaskContent fields, including paths, rundll32/.wll/#1 command fragments, and task names such as “OneDrive” or “Sens Api”.
references:
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4698
- https://labs.withsecure.com/publications/kapeka
- https://app.any.run/tasks/1efb3ed4-cc0f-4690-a0ed-24516809bc72/
- https://www.virustotal.com/gui/file/bd07fb1e9b4768e7202de6cc454c78c6891270af02085c51fce5539db1386c3f/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2024/Malware/kapeka/win_security_malware_kapeka_backdoor_scheduled_task_creation.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2024-07-03
tags:
- attack.execution
- attack.privilege-escalation
- attack.persistence
- attack.t1053.005
- detection.emerging-threats
logsource:
product: windows
service: security
definition: "Requirements: The Advanced Audit Policy setting Object Access > Audit Other Object Access Events has to be configured to trigger this detection."
detection:
selection_eid:
EventID: 4698
selection_paths:
TaskContent|contains:
- :\ProgramData\
- \AppData\Local\
selection_command:
TaskContent|contains|all:
- rundll32
- .wll
- "#1"
selection_taskname:
TaskContent|contains:
- OneDrive
- Sens Api
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1