Endpoint
Windows Task Scheduler
About 2,600 selected events/day from ten Windows servers, with native XML and Winlogbeat-style ECS fields.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-task-scheduler-operational/generator.yml \
--id tasks \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 129 | Task process created | One per run | process |
| 100 | Task started | One per run | process |
| 200 | Action started | One per run | process |
| 201 | Action completed | One per run, usually return code 0 | process |
| 102 | Task completed | One per run | process |
| 106 | Task registered | Temporary work and policy replacements | configuration |
| 141 | Task deleted | Temporary cleanup and policy replacements | configuration |
| 140 | Task updated | Occasional administrative changes | configuration |
Realism Features
- Run records retain their instance GUID and process identity
- Temporary tasks have independent SYSTEM cleanup after two to three hours
- Selected Server 2019 provider profile; trigger and startup-failure records are omitted
Sample Output
{
"@timestamp": "2026-09-01T00:54:26.472Z",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "task-deleted",
"category": [
"configuration"
],
"code": "141",
"kind": "event",
"original": "\u003cEvent xmlns=\"http://schemas.microsoft.com/win/2004/08/events/event\"\u003e\u003cSystem\u003e\u003cProvider Name=\"Microsoft-Windows-TaskScheduler\" Guid=\"{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}\"/\u003e\u003cEventID\u003e141\u003c/EventID\u003e\u003cVersion\u003e0\u003c/Version\u003e\u003cLevel\u003e4\u003c/Level\u003e\u003cTask\u003e141\u003c/Task\u003e\u003cOpcode\u003e0\u003c/Opcode\u003e\u003cKeywords\u003e0x8000000000000000\u003c/Keywords\u003e\u003cTimeCreated SystemTime=\"2026-09-01T00:54:26.4724655Z\"/\u003e\u003cEventRecordID\u003e785173\u003c/EventRecordID\u003e\u003cCorrelation/\u003e\u003cExecution ProcessID=\"1472\" ThreadID=\"400\"/\u003e\u003cChannel\u003eMicrosoft-Windows-TaskScheduler/Operational\u003c/Channel\u003e\u003cComputer\u003eAPP02.corp.contoso.test\u003c/Computer\u003e\u003cSecurity UserID=\"S-1-5-18\"/\u003e\u003c/System\u003e\u003cEventData Name=\"TaskDeleted\"\u003e\u003cData Name=\"TaskName\"\u003e\\Collect-Logs-56bfd7c2-f27c-4394-9252-c845e446b1d5\u003c/Data\u003e\u003cData Name=\"UserName\"\u003eCORP\\adm_rpatel\u003c/Data\u003e\u003c/EventData\u003e\u003c/Event\u003e",
"provider": "Microsoft-Windows-TaskScheduler",
"type": [
"deletion"
]
},
"host": {
"ip": [
"10.20.2.32"
],
"name": "APP02.corp.contoso.test"
},
"log": {
"level": "information"
},
"message": "User \"CORP\\adm_rpatel\" deleted Task Scheduler task \"\\Collect-Logs-56bfd7c2-f27c-4394-9252-c845e446b1d5\"",
"related": {
"user": [
"adm_rpatel"
]
},
"user": {
"domain": "CORP",
"name": "adm_rpatel"
},
"winlog": {
"channel": "Microsoft-Windows-TaskScheduler/Operational",
"computer_name": "APP02.corp.contoso.test",
"event_data": {
"TaskName": "\\Collect-Logs-56bfd7c2-f27c-4394-9252-c845e446b1d5",
"UserName": "CORP\\adm_rpatel"
},
"event_id": "141",
"process": {
"pid": 1472,
"thread": {
"id": 400
}
},
"provider_guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
"provider_name": "Microsoft-Windows-TaskScheduler",
"record_id": 785173,
"user": {
"identifier": "S-1-5-18"
},
"version": 0
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include recurring correlated episodes |
| anomaly_interval_hours | 24 | Hours between episode starts, from 6 to 8760 |
Related Generators
Endpoint
Windows Security Event Log
The Security channel of Windows Event Log — logon/logoff sessions, process creation, privilege escalation, account management, and audit policy changes from a 120-host Active Directory fleet.
Endpoint
Windows PowerShell
PowerShell classic and operational channels — engine lifecycle, script block logging, module invocations, pipeline execution, and provider starts. Includes obfuscated command detection and suspicious script patterns.
Endpoint
Windows Sysmon
Sysmon (System Monitor) operational channel — process creation with full command lines, network connections, file creates, registry modifications, DNS queries, and WMI events. SwiftOnSecurity-style tuning.