What are Windows scheduled tasks?
Task Scheduler runs programs at boot, at logon, on a timetable, on an event or when the machine is idle. Windows ships with hundreds of tasks of its own, and software installers add more. It is also one of the most common ways attackers keep access to a machine (MITRE ATT&CK T1053.005).
Every task exists in two places: an XML definition on disk and a cache in the SOFTWARE registry hive that Task Scheduler actually loads. Comparing the two is how you find tasks that were hidden, tampered with or had their files deleted.
Where the evidence is stored
- C:\Windows\System32\Tasks\ — one XML file per task (UTF-16LE, no extension): author, registration date, triggers, the account it runs as, settings, and the actions (command line, COM handler).
- SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache — Tree (task paths with Id, Index and SD values) and Tasks\{GUID} (Path, Hash, Actions, Triggers and DynamicInfo with creation and last-run FILETIMEs).
- C:\Windows\Tasks\*.job — legacy Task Scheduler 1.0 jobs: application, parameters, author, last run time.
- Related logs (not parsed here): Security event IDs 4698–4702 when object-access auditing is on, and Microsoft-Windows-TaskScheduler/Operational (106 registered, 140 updated, 141 deleted, 200/201 action started/completed).
What this tool checks
- Hidden tasks: a TaskCache Tree entry without its SD value (the "Tarrask" technique) — invisible to schtasks and the console, still running.
- Deleted or planted files: tasks registered without an XML file, and XML files with no registration; XML files edited after registration (TaskCache hash) and registry actions that differ from the file.
- Suspicious content: encoded PowerShell (decoded for you), LOLBins, commands in user-writable or network paths, SYSTEM or highest privileges for non-Microsoft tasks, hidden non-Microsoft tasks, random-looking names and recently registered tasks.
- Times: registration date, TaskCache creation, last run and last successful run, trigger start boundaries and registry key last-write times, on one filterable timeline.
Limitations
- Registry transaction logs are not replayed: a dirty hive is flagged, but changes still in SOFTWARE.LOG1/LOG2 are missing.
- TaskCache binary values (DynamicInfo, Actions, Triggers) are undocumented; their layouts come from public reverse engineering. Only the Triggers header and principal are decoded, not every trigger record.
- XML dates, trigger times and .job times are local time without a zone; the offset is inferred when possible, and shown.
- Deleted registry keys and deleted XML files are not carved; the event logs and volume shadow copies are the places to look for those.
How to get the files
- Collect C:\Windows\System32\Tasks (and C:\Windows\Tasks) plus the SOFTWARE hive with KAPE (ScheduledTasks + RegistryHivesSystem), Velociraptor (Windows.Triage.Targets) or reg save and a copy of the folder.
- Keep the folder structure (…\Windows\System32\Tasks, …\Windows\System32\config\SOFTWARE) so tasks are matched with the right hive when a ZIP holds several machines.
- Collect the complete Tasks folder: missing XML files are only flagged when most registered tasks have theirs.
FAQ
Are my files uploaded anywhere?
No. The parser — including its registry and XML readers — is Rust compiled to WebAssembly and runs in a Web Worker in your browser. There is no upload endpoint.
How does it find hidden (Tarrask) tasks?
Task Scheduler lists a task only if its TaskCache\Tree key has an SD (security descriptor) value. Malware with SYSTEM rights can delete that value: the task disappears from schtasks and the console but keeps running. The tool flags every Tree key that has a task Id but no SD, and shows the key's last-write time.
Why do I need both the Tasks folder and the SOFTWARE hive?
Each tells half the story. The XML file is the readable definition; the TaskCache is what Task Scheduler actually loads. Tasks registered with no XML file, files that were never registered, XML edited after registration and registry actions that differ from the file only show up when both are compared.
Why are the times shifted?
Windows writes the registration date and trigger times in task XML as local time without a time zone, while TaskCache times are UTC. The tool infers the machine's offset by comparing the two for the same tasks, and you can set it yourself.
Is a flagged task malicious?
Not necessarily. Findings are pointers for triage: third-party updaters run as SYSTEM from ProgramData, some management tools use encoded PowerShell. Read the explanation on each finding and corroborate with other artifacts.