Skip to content
Task Scheduler

Task Scheduler Event ID 100: Task started

Task StartedTask Scheduler event 100 marks the start of a task instance: task path, run-as user and an instance GUID that links the launch, actions and completion.
100
Event ID
100
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 100 means

Event 100 is written each time the Task Scheduler service starts an instance of a task, whatever the trigger: schedule, logon, startup, an event, or a manual run. It records the task path (TaskName), the account the task runs under (UserContext) and an InstanceId GUID unique to this run.

The InstanceId is the thread through the rest of the run: the actions launched (200, with the same value in TaskInstanceId), the actions completed (201) and the instance finishing (102). Event 129 gives the process ID and image of the process created for the task, and is the bridge to process creation logs (Security 4688, Sysmon 1).

Built-in maintenance tasks make this event very frequent. It is most useful as a timestamp source: when exactly did a suspicious task run, and as whom.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the task in the library, e.g. \Microsoft\Windows\UpdateOrchestrator\Schedule Scan.
UserContextAccount the task instance runs as. NT AUTHORITY\SYSTEM for many built-in tasks; a user or service account for others.
InstanceIdGUID of this run of the task. The same value appears as TaskInstanceId in 200 and 201 and as InstanceId in 102.

Common benign sources

  • Built-in Windows maintenance, update, telemetry and defragmentation tasks, often dozens per hour.
  • Application updaters (browsers, Office, vendor agents) running on their schedules.
  • Tasks deployed by GPO or management tools running as configured.

What attackers do that produces it

  • Persistence tasks firing at logon, startup or on a timer.
  • A freshly registered (106) task running for the first time, often under SYSTEM, to execute a payload remotely.

Investigation tips

  • Filter out known built-in task paths, then review the remaining TaskName values and their run frequency.
  • Pivot on InstanceId to 200/201 for the action and its result code, and use 129 for the process ID.
  • Match the run time and process ID with Security 4688 or Sysmon 1 (parent is usually the svchost.exe hosting the Schedule service; taskeng.exe on Windows 7 era systems) for the full command line.
  • For unknown tasks, look back for 106 or 140 to see who created or changed the task and when.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading