Skip to content
Task Scheduler

Task Scheduler Event ID 102: Task completed

Task completedTask Scheduler event 102 marks the end of a task instance. With event 100 it bounds how long a task ran; the action's return code is in event 201.
102
Event ID
102
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 102 means

Event 102 is written when the Task Scheduler service considers a task instance finished. It carries the same three fields as event 100 — TaskName, UserContext and InstanceId — so the pair 100/102 with a matching InstanceId gives the start and end time of one run.

"Successfully finished" refers to the scheduler's handling of the instance, not to the outcome of the program it launched. The exit code of each action is recorded in event 201 (ResultCode), which is where to look to know whether the payload or script actually succeeded.

A task that starts (100) but never logs 102 may still be running, may have been killed, or may have been interrupted by a reboot.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the task in the library.
UserContextAccount the task instance ran as.
InstanceIdGUID of the run; matches InstanceId in 100 and TaskInstanceId in 200/201.

Common benign sources

  • Completion of built-in maintenance and update tasks, in large numbers.
  • Application and management tasks finishing their scheduled work.

What attackers do that produces it

  • The end of a malicious task run; a very short run time is typical of a launcher that spawns a payload and exits.
  • One-shot remote execution tasks, usually followed by deletion (141).

Investigation tips

  • Pair 100 and 102 by InstanceId to compute run duration for suspicious tasks.
  • Read 201 for the same instance to get the action's ResultCode.
  • Look for 141 shortly after 102 for the same TaskName — task used once then removed.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading