Task Scheduler Event ID 129: Task process created
- Event ID
- 129
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 129 means
Event 129 is written when the Task Scheduler service creates a process to carry out a task's executable action. The record holds the task path (TaskName), the image that was launched (Path), its ProcessID and the process Priority.
This is the event that turns a scheduled task into something you can find in process telemetry. Take the ProcessID and timestamp to Security 4688 or Sysmon 1 to get the full command line, the parent process and the hashes, then follow the process tree from there.
Tasks whose action is a COM handler rather than a program do not necessarily create a new process of their own; in that case the work runs inside a task host process and 129 may not tell the whole story.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the task in the library. |
| Path | Image path of the process launched for the task, e.g. C:\Windows\System32\cmd.exe. Script hosts and LOLBins here (powershell.exe, cmd.exe, mshta.exe, rundll32.exe) deserve review. |
| ProcessID | Process ID of the created process. Pivot on it (with the timestamp) to 4688 / Sysmon 1. |
| Priority | Priority class assigned to the task process, taken from the task settings. |
Common benign sources
- Built-in and vendor tasks launching their own binaries from
System32orProgram Files. - Admin scripts run by scheduled tasks through
powershell.exeorcmd.exe.
What attackers do that produces it
- Payloads launched from user-writable paths (
AppData,Temp,ProgramData,Public) by a scheduled task. - Tasks launching
powershell.exe,cmd.exe,mshta.exe,rundll32.exeorregsvr32.exeto proxy execution.
Investigation tips
- Stack Path values across hosts; rare images or user-writable directories stand out quickly.
- Match ProcessID and time with Security 4688 or Sysmon 1 for the command line and hashes.
- Walk back to 106 or 140 for the same TaskName to find who created or modified the task.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 2
- MediumScheduled Task Executed From A Suspicious LocationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumScheduled Task Executed Uncommon LOLBINRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.