Task Scheduler Event ID 141: Task deleted
- Event ID
- 141
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 141 means
Event 141 is written when a task is removed from the Task Scheduler library, whether through schtasks /delete, Unregister-ScheduledTask, the console or a remote API call. It records the task path (TaskName) and the account that deleted it (UserName).
On its own a deletion is mundane — uninstallers remove their tasks all the time. Its value is in sequence: a task registered (106), launched (100, 129, 200) and deleted (141) within a few seconds or minutes is the typical footprint of remote execution tools that use the scheduler as a transport, and of attackers cleaning up persistence.
Once the task is deleted its XML file and registry keys are gone, so the Operational log (and Security 4698/4699 if enabled) may be the only remaining trace of what ran.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the deleted task in the task library. |
| UserName | Account that deleted the task (DOMAIN\user or NT AUTHORITY\SYSTEM). |
Common benign sources
- Uninstallers removing their scheduled tasks.
- Windows servicing retiring built-in tasks during feature updates.
- Administrators cleaning up obsolete or duplicated tasks.
What attackers do that produces it
- Remote execution tools that create a task, run it once and delete it (for example Impacket
atexec). - Cleanup of persistence tasks after the objective is reached, or to hinder investigation.
Investigation tips
- Look backward for 106 with the same TaskName to measure the task's lifetime; seconds or minutes is suspicious.
- Pull 100, 129, 200 and 201 for the same TaskName to find what ran and its process ID.
- Use Security 4698/4699 (if audited) to recover the task XML that was deleted.
- Correlate UserName with network logons (Security 4624 type 3) at the same time to find the source host.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighImportant Scheduled Task Deleted or DisabledRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.