Event ID 4700: Scheduled task enabled
- Event ID
- 4700
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 4700 means
Event 4700 is written when a disabled scheduled task is enabled. The record includes the task's XML (TaskContent), so you see exactly what the re-enabled task will run.
It is uncommon in day-to-day operations compared with creation and modification. It matters when an attacker reactivates an existing task — a built-in or third-party task whose action has been replaced, or a malicious task staged disabled and switched on later — because reusing an existing task name draws less attention than creating a new one.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Other Object Access Events (Success). Not enabled in the default audit policy.
No SACL is needed. Recent Windows builds add ClientProcessId, ParentProcessId, ClientProcessStartKey, RpcCallClientLocality and FQDN to identify the process that made the request. The Task Scheduler Operational log records similar lifecycle events (106, 140, 141) without audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change. For remote task management (schtasks /s, Impacket) this is the remote account. |
| SubjectDomainName | Domain or computer name of that account. |
| SubjectLogonId | Logon session of the account; pivot to 4624 on the same host to find where it came from. |
| TaskName | Full task path, e.g. \Microsoft\Windows\... for built-in tasks. Tasks at the root (\Name) or with names mimicking Microsoft ones deserve a look. |
| TaskContent | The task's full XML definition. Read Actions/Exec/Command and Arguments (what runs), Principals (UserId, RunLevel — HighestAvailable means elevated), Triggers and Settings/Hidden. |
| ClientProcessId | PID of the process that requested the change, on builds that log it. Match it to 4688. |
Common benign sources
- Software or administrators re-enabling maintenance tasks after troubleshooting.
- Updaters toggling their own tasks during upgrades.
What attackers do that produces it
- Re-enabling a previously disabled task whose action points to a payload, to gain persistence without a new 4698.
- Enabling a staged task on many hosts at the same time.
Investigation tips
- Compare TaskContent with the last known 4698/4702 for the same TaskName to see whether the action changed before it was enabled.
- Pivot on SubjectLogonId to the logon that performed the change.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.