Skip to content
Security

Event ID 4699: Scheduled task deleted

A scheduled task was deletedSecurity event 4699 records a deleted scheduled task, including its last XML definition. Quick create-then-delete pairs point to remote execution.
4699
Event ID
4699
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 4699 means

Event 4699 is written when a scheduled task is removed. Like 4698, it carries the task's XML in TaskContent, so even after the task is gone you can still read what it ran and as whom.

Deletion on its own is common — uninstallers and updaters clean up after themselves. It becomes significant when it closely follows the creation of the same task: tools that execute commands remotely through the Task Scheduler (Impacket atexec, scripted schtasks /create /s ... & schtasks /run & schtasks /delete) leave exactly that pattern. Attackers also delete their persistence tasks when cleaning up.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Other Object Access Events (Success). Not enabled in the default audit policy.

No SACL is needed. Recent Windows builds add ClientProcessId, ParentProcessId, ClientProcessStartKey, RpcCallClientLocality and FQDN to identify the process that made the request. The Task Scheduler Operational log records similar lifecycle events (106, 140, 141) without audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change. For remote task management (schtasks /s, Impacket) this is the remote account.
SubjectDomainNameDomain or computer name of that account.
SubjectLogonIdLogon session of the account; pivot to 4624 on the same host to find where it came from.
TaskNameFull task path, e.g. \Microsoft\Windows\... for built-in tasks. Tasks at the root (\Name) or with names mimicking Microsoft ones deserve a look.
TaskContentThe task's full XML definition. Read Actions/Exec/Command and Arguments (what runs), Principals (UserId, RunLevel — HighestAvailable means elevated), Triggers and Settings/Hidden.
ClientProcessIdPID of the process that requested the change, on builds that log it. Match it to 4688.

Common benign sources

  • Software uninstalls and updates removing their tasks.
  • Windows servicing replacing built-in tasks.

What attackers do that produces it

  • Remote command execution through the Task Scheduler: 4698 and 4699 for the same TaskName seconds apart, created by a remote account.
  • Cleanup of persistence tasks at the end of an intrusion to remove evidence.

Investigation tips

  • Match each 4699 to a 4698 with the same TaskName and compute the lifetime; seconds-long tasks are suspicious.
  • Read TaskContent to recover the command that was executed, even though the task no longer exists.
  • Check Task Scheduler Operational 141 (task deleted) and 200/201 to confirm the task actually ran before deletion.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation
T1070 Indicator RemovalStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading