Skip to content
Task Scheduler

Task Scheduler Event ID 200: Action started

Action startedTask Scheduler event 200 records that a task action was launched: which task, which instance and the action itself — often the program path that ran.
200
Event ID
200
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 200 means

Event 200 is written when the Task Scheduler launches one of a task's actions. It records the task path (TaskName), the action (ActionName) and the run's TaskInstanceId, which matches the InstanceId of the 100 event that started the instance.

For executable actions, ActionName shows the program that was started, which makes 200 one of the quickest ways to see what a task actually does without opening its XML. For COM handler actions it shows the handler instead. Arguments are not included; get them from the task definition or from process creation logs.

Each action produces its own 200, so a task with several actions logs several 200 events under one instance, each followed by a 201 when it completes.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the task in the library.
ActionNameThe action launched — for an executable action, the program path (e.g. C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe).
TaskInstanceIdGUID of the task run; same value as InstanceId in 100 and 102.

Common benign sources

  • Built-in tasks launching System32 binaries or COM handlers.
  • Vendor updaters and management agents launching their executables from Program Files.

What attackers do that produces it

  • Tasks launching payloads from user-writable folders or script interpreters with encoded arguments.
  • Persistence tasks whose action points to a renamed or look-alike binary.

Investigation tips

  • Stack ActionName across hosts to find rare programs launched by tasks.
  • Pivot on TaskInstanceId to 100 (start, run-as user), 201 (result code) and 102 (end).
  • Use 129 or process creation logs at the same time to recover the full command line.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading