Skip to content
Security

Event ID 4700: Scheduled task enabled

A scheduled task was enabledSecurity event 4700 records a scheduled task being enabled, with its XML definition. Watch for dormant or attacker-created tasks switched back on.
4700
Event ID
4700
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 4700 means

Event 4700 is written when a disabled scheduled task is enabled. The record includes the task's XML (TaskContent), so you see exactly what the re-enabled task will run.

It is uncommon in day-to-day operations compared with creation and modification. It matters when an attacker reactivates an existing task — a built-in or third-party task whose action has been replaced, or a malicious task staged disabled and switched on later — because reusing an existing task name draws less attention than creating a new one.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Other Object Access Events (Success). Not enabled in the default audit policy.

No SACL is needed. Recent Windows builds add ClientProcessId, ParentProcessId, ClientProcessStartKey, RpcCallClientLocality and FQDN to identify the process that made the request. The Task Scheduler Operational log records similar lifecycle events (106, 140, 141) without audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change. For remote task management (schtasks /s, Impacket) this is the remote account.
SubjectDomainNameDomain or computer name of that account.
SubjectLogonIdLogon session of the account; pivot to 4624 on the same host to find where it came from.
TaskNameFull task path, e.g. \Microsoft\Windows\... for built-in tasks. Tasks at the root (\Name) or with names mimicking Microsoft ones deserve a look.
TaskContentThe task's full XML definition. Read Actions/Exec/Command and Arguments (what runs), Principals (UserId, RunLevel — HighestAvailable means elevated), Triggers and Settings/Hidden.
ClientProcessIdPID of the process that requested the change, on builds that log it. Match it to 4688.

Common benign sources

  • Software or administrators re-enabling maintenance tasks after troubleshooting.
  • Updaters toggling their own tasks during upgrades.

What attackers do that produces it

  • Re-enabling a previously disabled task whose action points to a payload, to gain persistence without a new 4698.
  • Enabling a staged task on many hosts at the same time.

Investigation tips

  • Compare TaskContent with the last known 4698/4702 for the same TaskName to see whether the action changed before it was enabled.
  • Pivot on SubjectLogonId to the logon that performed the change.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading