Event ID 4701: Scheduled task disabled
- Event ID
- 4701
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 4701 means
Event 4701 is written when a scheduled task is disabled. The TaskContent XML shows the task definition with <Enabled>false</Enabled>.
Legitimate disabling happens during troubleshooting or software changes. From an attacker's perspective, disabling tasks is a way to stop things that would interfere: antivirus scans and signature updates, backup jobs, or Windows maintenance tasks. It can also be the first half of a disable-modify-enable sequence on an existing task.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Other Object Access Events (Success). Not enabled in the default audit policy.
No SACL is needed. Recent Windows builds add ClientProcessId, ParentProcessId, ClientProcessStartKey, RpcCallClientLocality and FQDN to identify the process that made the request. The Task Scheduler Operational log records similar lifecycle events (106, 140, 141) without audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change. For remote task management (schtasks /s, Impacket) this is the remote account. |
| SubjectDomainName | Domain or computer name of that account. |
| SubjectLogonId | Logon session of the account; pivot to 4624 on the same host to find where it came from. |
| TaskName | Full task path, e.g. \Microsoft\Windows\... for built-in tasks. Tasks at the root (\Name) or with names mimicking Microsoft ones deserve a look. |
| TaskContent | The task's full XML definition. Read Actions/Exec/Command and Arguments (what runs), Principals (UserId, RunLevel — HighestAvailable means elevated), Triggers and Settings/Hidden. |
| ClientProcessId | PID of the process that requested the change, on builds that log it. Match it to 4688. |
Common benign sources
- Administrators disabling noisy or broken tasks.
- Software uninstallers or policies turning off vendor update tasks.
What attackers do that produces it
- Disabling security-tool, backup or Windows Defender scheduled tasks before deploying ransomware.
- Temporarily disabling a legitimate task to modify its action (4702) and re-enable it (4700).
Investigation tips
- Review which tasks were disabled and by whom; security, backup and update tasks deserve immediate attention.
- Look for 4702 and 4700 on the same TaskName right after, which indicates tampering rather than simple maintenance.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighImportant Scheduled Task Deleted/DisabledRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.