Skip to content
Task Scheduler

Task Scheduler Event ID 141: Task deleted

Task registration deletedTask Scheduler event 141 records that a user deleted a scheduled task. Right after 106 and a run, it points to one-shot remote execution or cleanup.
141
Event ID
141
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 141 means

Event 141 is written when a task is removed from the Task Scheduler library, whether through schtasks /delete, Unregister-ScheduledTask, the console or a remote API call. It records the task path (TaskName) and the account that deleted it (UserName).

On its own a deletion is mundane — uninstallers remove their tasks all the time. Its value is in sequence: a task registered (106), launched (100, 129, 200) and deleted (141) within a few seconds or minutes is the typical footprint of remote execution tools that use the scheduler as a transport, and of attackers cleaning up persistence.

Once the task is deleted its XML file and registry keys are gone, so the Operational log (and Security 4698/4699 if enabled) may be the only remaining trace of what ran.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the deleted task in the task library.
UserNameAccount that deleted the task (DOMAIN\user or NT AUTHORITY\SYSTEM).

Common benign sources

  • Uninstallers removing their scheduled tasks.
  • Windows servicing retiring built-in tasks during feature updates.
  • Administrators cleaning up obsolete or duplicated tasks.

What attackers do that produces it

  • Remote execution tools that create a task, run it once and delete it (for example Impacket atexec).
  • Cleanup of persistence tasks after the objective is reached, or to hinder investigation.

Investigation tips

  • Look backward for 106 with the same TaskName to measure the task's lifetime; seconds or minutes is suspicious.
  • Pull 100, 129, 200 and 201 for the same TaskName to find what ran and its process ID.
  • Use Security 4698/4699 (if audited) to recover the task XML that was deleted.
  • Correlate UserName with network logons (Security 4624 type 3) at the same time to find the source host.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation
T1070.009 Indicator Removal: Clear PersistenceStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading