Task Scheduler Event ID 100: Task started
- Event ID
- 100
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 100 means
Event 100 is written each time the Task Scheduler service starts an instance of a task, whatever the trigger: schedule, logon, startup, an event, or a manual run. It records the task path (TaskName), the account the task runs under (UserContext) and an InstanceId GUID unique to this run.
The InstanceId is the thread through the rest of the run: the actions launched (200, with the same value in TaskInstanceId), the actions completed (201) and the instance finishing (102). Event 129 gives the process ID and image of the process created for the task, and is the bridge to process creation logs (Security 4688, Sysmon 1).
Built-in maintenance tasks make this event very frequent. It is most useful as a timestamp source: when exactly did a suspicious task run, and as whom.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the task in the library, e.g. \Microsoft\Windows\UpdateOrchestrator\Schedule Scan. |
| UserContext | Account the task instance runs as. NT AUTHORITY\SYSTEM for many built-in tasks; a user or service account for others. |
| InstanceId | GUID of this run of the task. The same value appears as TaskInstanceId in 200 and 201 and as InstanceId in 102. |
Common benign sources
- Built-in Windows maintenance, update, telemetry and defragmentation tasks, often dozens per hour.
- Application updaters (browsers, Office, vendor agents) running on their schedules.
- Tasks deployed by GPO or management tools running as configured.
What attackers do that produces it
- Persistence tasks firing at logon, startup or on a timer.
- A freshly registered (106) task running for the first time, often under
SYSTEM, to execute a payload remotely.
Investigation tips
- Filter out known built-in task paths, then review the remaining TaskName values and their run frequency.
- Pivot on InstanceId to 200/201 for the action and its result code, and use 129 for the process ID.
- Match the run time and process ID with Security 4688 or Sysmon 1 (parent is usually the
svchost.exehosting the Schedule service;taskeng.exeon Windows 7 era systems) for the full command line. - For unknown tasks, look back for 106 or 140 to see who created or changed the task and when.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.