Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a scheduled-task event?

A scheduled-task event records a stage in the life of an automatically triggered task. It may describe creation, modification, launch or status, and does not necessarily show that a person was present when the task ran.

Trigger, execution and outcome are separate stages

A task can run at a fixed time, at startup or login, at intervals, or in response to another event. It can launch a program or script under a user, service, administrator or system account.

A scheduler's “completed” entry may mean only that it handed control to the program. Process and application records are needed to establish whether the intended operation actually succeeded.

The task definition explains later activity

Preserve its name, triggers, action, executable path, arguments, account context and creation or modification history. Link launch records to process ancestry, file activity and network connections. Authentication and administration logs may identify who created or altered the definition.

Scheduled tasks support routine maintenance as well as persistence and remote administration. Classify the mechanism first, then test whether its configuration, timing and provenance fit authorised use. Do not attribute a run to the person named in its execution account without evidence of their involvement.

The point to remember

Separate who configured a scheduled task, what triggered it and whether its launched program completed successfully.

Reference: LOG-076Logs, Records & Provider Evidence