Dikshant Lather.
Our Story Write Sign In Get Started
Home Our Story Stories Blueprints Advisory Resume Contact
Home / Stories / Topic

EventID 4698

Topic • 1 Story
Related: KQL Cloud Security Azure DevSecOps Entra ID Microsoft Sentinel AI Security Threat Hunting
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting Persistence via Windows Scheduled Task Creation Using KQL

Hunt for adversary persistence via unauthorized Windows Scheduled Tasks by parsing Security Event ID 4698 and DeviceProcessEvents in KQL.

Threat Hunting 2 min read
0 0
Detecting Persistence via Windows Scheduled Task Creation Using KQL
Dikshant Lather.

Cybersecurity Consultant specializing in CSPM, Microsoft Defender for Cloud, and AI Security architecture. Open for consulting advisory.

Directory

  • Home
  • Our Story & Bio
  • Resume & Certs
  • Advisory Services
  • Security Blueprints
  • Contact & Inquiries

Publications

  • All Stories
  • Become a Contributor
  • RSS 2.0 Feed
  • Atom 1.0 Feed
  • XML Sitemap

Dispatch

Briefings on CSPM playbooks, Azure hardening, and AI defense patterns.

© 2026 Dikshant Lather • All rights reserved.

Privacy Terms Cookies
ESC
Navigate ↑↓ • Select ↵
Dikshant Lather.