Skip to content
Task Scheduler

Task Scheduler Event ID 129: Task process created

Created Task ProcessTask Scheduler event 129 records the process created for a task: task path, image path and process ID — the link to process creation logs.
129
Event ID
129
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 129 means

Event 129 is written when the Task Scheduler service creates a process to carry out a task's executable action. The record holds the task path (TaskName), the image that was launched (Path), its ProcessID and the process Priority.

This is the event that turns a scheduled task into something you can find in process telemetry. Take the ProcessID and timestamp to Security 4688 or Sysmon 1 to get the full command line, the parent process and the hashes, then follow the process tree from there.

Tasks whose action is a COM handler rather than a program do not necessarily create a new process of their own; in that case the work runs inside a task host process and 129 may not tell the whole story.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the task in the library.
PathImage path of the process launched for the task, e.g. C:\Windows\System32\cmd.exe. Script hosts and LOLBins here (powershell.exe, cmd.exe, mshta.exe, rundll32.exe) deserve review.
ProcessIDProcess ID of the created process. Pivot on it (with the timestamp) to 4688 / Sysmon 1.
PriorityPriority class assigned to the task process, taken from the task settings.

Common benign sources

  • Built-in and vendor tasks launching their own binaries from System32 or Program Files.
  • Admin scripts run by scheduled tasks through powershell.exe or cmd.exe.

What attackers do that produces it

  • Payloads launched from user-writable paths (AppData, Temp, ProgramData, Public) by a scheduled task.
  • Tasks launching powershell.exe, cmd.exe, mshta.exe, rundll32.exe or regsvr32.exe to proxy execution.

Investigation tips

  • Stack Path values across hosts; rare images or user-writable directories stand out quickly.
  • Match ProcessID and time with Security 4688 or Sysmon 1 for the command line and hashes.
  • Walk back to 106 or 140 for the same TaskName to find who created or modified the task.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading