Task Scheduler Event ID 200: Action started
- Event ID
- 200
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 200 means
Event 200 is written when the Task Scheduler launches one of a task's actions. It records the task path (TaskName), the action (ActionName) and the run's TaskInstanceId, which matches the InstanceId of the 100 event that started the instance.
For executable actions, ActionName shows the program that was started, which makes 200 one of the quickest ways to see what a task actually does without opening its XML. For COM handler actions it shows the handler instead. Arguments are not included; get them from the task definition or from process creation logs.
Each action produces its own 200, so a task with several actions logs several 200 events under one instance, each followed by a 201 when it completes.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the task in the library. |
| ActionName | The action launched — for an executable action, the program path (e.g. C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe). |
| TaskInstanceId | GUID of the task run; same value as InstanceId in 100 and 102. |
Common benign sources
- Built-in tasks launching
System32binaries or COM handlers. - Vendor updaters and management agents launching their executables from
Program Files.
What attackers do that produces it
- Tasks launching payloads from user-writable folders or script interpreters with encoded arguments.
- Persistence tasks whose action points to a renamed or look-alike binary.
Investigation tips
- Stack ActionName across hosts to find rare programs launched by tasks.
- Pivot on TaskInstanceId to 100 (start, run-as user), 201 (result code) and 102 (end).
- Use 129 or process creation logs at the same time to recover the full command line.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.