Task Scheduler Event ID 201: Action completed
- Event ID
- 201
- Channel
- Microsoft-Windows-TaskScheduler/Operational
- Provider
- Microsoft-Windows-TaskScheduler
- Log file
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Category
- Scheduled tasks
- Default logging
- Needs configuration
What event 201 means
Event 201 is written when an action launched by a task (event 200) completes. It records the task path (TaskName), the TaskInstanceId of the run, the action (ActionName) and, in current versions of the event, the ResultCode returned by the action.
For executable actions the result code is the process exit code: 0 usually means success, anything else is program-specific. That makes 201 the place to confirm whether a suspicious task actually did its job, and the gap between 200 and 201 shows how long the action ran.
Older versions of the event omit ResultCode, so its absence does not mean success.
When it is logged
The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.
The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.
Key fields
| Field | What it tells you |
|---|---|
| TaskName | Full path of the task in the library. |
| TaskInstanceId | GUID of the task run; links to 100, 200 and 102. |
| ActionName | The action that completed — for executable actions, the program path. |
| ResultCode | Return code of the action (the process exit code for executable actions). 0 is the usual success value; other values are defined by the program. |
Common benign sources
- Built-in and vendor tasks completing with
0or with known, harmless error codes. - Tasks failing repeatedly because a program was uninstalled or a path changed.
What attackers do that produces it
- Completion of a persistence or remote execution task, confirming the payload ran.
- Non-zero codes on a new task can reveal failed attempts (blocked by AV or AppLocker, wrong path).
Investigation tips
- Pair 200 and 201 by TaskInstanceId to get the action's run time and outcome.
- For failed actions of suspicious tasks, check Defender and AppLocker logs at the same time for a block.
- Correlate with process creation and termination logs (Security 4688/4689, Sysmon 1) for the same program.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1053.005 Scheduled Task/Job: Scheduled Task | Execution, Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.