Task Scheduler Event ID 142: Task disabled
- Event ID
- 142
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 142 means
Event 142 is written when a registered task is disabled, for example with schtasks /change /disable, Disable-ScheduledTask or the console. The task stays in the library but will no longer run on its triggers. The record holds the task path (TaskName) and the account that disabled it (UserName).
Most disables are routine administration. What matters is which task: tasks that run antivirus scans or signature updates, Windows Update, backups or log collection are the ones an attacker wants silenced, and a disable is quieter than a deletion.
If object access auditing is enabled, Security event 4701 records the same action with the task XML, which helps confirm what the disabled task used to do.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the disabled task in the task library. |
| UserName | Account that disabled the task (DOMAIN\user or NT AUTHORITY\SYSTEM). |
Common benign sources
- Administrators or optimization scripts disabling telemetry, consumer or vendor tasks.
- Software disabling its own updater task when a setting is changed.
What attackers do that produces it
- Disabling security product, Windows Update or backup tasks before deploying ransomware or other payloads.
- Disabling a legitimate task so a look-alike malicious task can take its place.
Investigation tips
- Review TaskName against a list of tasks that must stay enabled (AV, update, backup, monitoring agents).
- Check whether UserName is an expected admin account and whether the change came during a known maintenance window.
- Look for other defense tampering around the same time (service stops, Defender configuration changes).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighImportant Scheduled Task Deleted or DisabledRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.