Skip to content
Task Scheduler

Task Scheduler Event ID 201: Action completed

Action completedTask Scheduler event 201 records that a task action completed, with the action and its return code — tells you whether the launched program succeeded.
201
Event ID
201
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 201 means

Event 201 is written when an action launched by a task (event 200) completes. It records the task path (TaskName), the TaskInstanceId of the run, the action (ActionName) and, in current versions of the event, the ResultCode returned by the action.

For executable actions the result code is the process exit code: 0 usually means success, anything else is program-specific. That makes 201 the place to confirm whether a suspicious task actually did its job, and the gap between 200 and 201 shows how long the action ran.

Older versions of the event omit ResultCode, so its absence does not mean success.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the task in the library.
TaskInstanceIdGUID of the task run; links to 100, 200 and 102.
ActionNameThe action that completed — for executable actions, the program path.
ResultCodeReturn code of the action (the process exit code for executable actions). 0 is the usual success value; other values are defined by the program.

Common benign sources

  • Built-in and vendor tasks completing with 0 or with known, harmless error codes.
  • Tasks failing repeatedly because a program was uninstalled or a path changed.

What attackers do that produces it

  • Completion of a persistence or remote execution task, confirming the payload ran.
  • Non-zero codes on a new task can reveal failed attempts (blocked by AV or AppLocker, wrong path).

Investigation tips

  • Pair 200 and 201 by TaskInstanceId to get the action's run time and outcome.
  • For failed actions of suspicious tasks, check Defender and AppLocker logs at the same time for a block.
  • Correlate with process creation and termination logs (Security 4688/4689, Sysmon 1) for the same program.

MITRE ATT&CK techniques

TechniqueTactics
T1053.005 Scheduled Task/Job: Scheduled TaskExecution, Persistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading