Task Scheduler Event ID 102: Task completed
- Event ID
- 102
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 102 means
Event 102 is written when the Task Scheduler service considers a task instance finished. It carries the same three fields as event 100 — TaskName, UserContext and InstanceId — so the pair 100/102 with a matching InstanceId gives the start and end time of one run.
"Successfully finished" refers to the scheduler's handling of the instance, not to the outcome of the program it launched. The exit code of each action is recorded in event 201 (ResultCode), which is where to look to know whether the payload or script actually succeeded.
A task that starts (100) but never logs 102 may still be running, may have been killed, or may have been interrupted by a reboot.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the task in the library. |
| UserContext | Account the task instance ran as. |
| InstanceId | GUID of the run; matches InstanceId in 100 and TaskInstanceId in 200/201. |
Common benign sources
- Completion of built-in maintenance and update tasks, in large numbers.
- Application and management tasks finishing their scheduled work.
What attackers do that produces it
- The end of a malicious task run; a very short run time is typical of a launcher that spawns a payload and exits.
- One-shot remote execution tasks, usually followed by deletion (141).
Investigation tips
- Pair 100 and 102 by InstanceId to compute run duration for suspicious tasks.
- Read 201 for the same instance to get the action's ResultCode.
- Look for 141 shortly after 102 for the same TaskName — task used once then removed.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.