Data Source: Windows Event Log TaskScheduler 200

Logs the successful registration of a new scheduled task in Windows Task Scheduler, including task details and configurations.

Property Value
Source WinEventLog:Microsoft-Windows-TaskScheduler/Operational
Sourcetype wineventlog
Separator EventCode
+ Fields

            1
            _time
          
            3
            ActionName
          
            5
            ActivityID
          
            7
            Channel
          
            9
            Computer
          
            11
            EnginePID
          
            13
            Error_Code
          
            15
            EventCode
          
            17
            EventData_Xml
          
            19
            EventID
          
            21
            EventRecordID
          
            23
            Guid
          
            25
            Keywords
          
            27
            Level
          
            29
            Name
          
            31
            Opcode
          
            33
            ProcessID
          
            35
            RecordNumber
          
            37
            SystemTime
          
            39
            System_Props_Xml
          
            41
            Task
          
            43
            TaskInstanceId
          
            45
            TaskName
          
            47
            ThreadID
          
            49
            UserID
          
            51
            Version
          
            53
            app
          
            55
            date_hour
          
            57
            date_mday
          
            59
            date_minute
          
            61
            date_month
          
            63
            date_second
          
            65
            date_wday
          
            67
            date_year
          
            69
            date_zone
          
            71
            dest
          
            73
            dvc
          
            75
            dvc_nt_host
          
            77
            event_id
          
            79
            eventtype
          
            81
            host
          
            83
            id
          
            85
            index
          
            87
            linecount
          
            89
            product
          
            91
            punct
          
            93
            signature_id
          
            95
            source
          
            97
            sourcetype
          
            99
            splunk_server
          
            101
            ta_windows_action
          
            103
            tag
          
            105
            tag::eventtype
          
            107
            timeendpos
          
            109
            timestartpos
          
            111
            user_id
          
            113
            vendor
          
            115
            vendor_product
          
            117
            
          
...
not set
1<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-TaskScheduler' Guid='{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}'/><EventID>200</EventID><Version>1</Version><Level>4</Level><Task>200</Task><Opcode>1</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime='2024-03-04T03:52:18.856458200Z'/><EventRecordID>4323</EventRecordID><Correlation ActivityID='{2EE32989-FAF3-4BA3-9FB9-DB0080598F68}'/><Execution ProcessID='988' ThreadID='4524'/><Channel>Microsoft-Windows-TaskScheduler/Operational</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security UserID='S-1-5-18'/></System><EventData Name='ActionStart'><Data Name='TaskName'>\OneLinerTestTask3</Data><Data Name='ActionName'>notepad.exe</Data><Data Name='TaskInstanceId'>{2EE32989-FAF3-4BA3-9FB9-DB0080598F68}</Data><Data Name='EnginePID'>536</Data></EventData></Event>
zed

Source: GitHub | Version: 2