Skip to content
TarraskFinds Tarrask-style hidden tasks — TaskCache vs. XML

Scheduled Tasks Parser

Every scheduled task on a Windows machine: the XML definitions, the TaskCache in the SOFTWARE hive and legacy .job files, matched up so hidden, deleted and tampered tasks stand out. Parsed in your browser with WebAssembly — nothing is uploaded.

  • System32\Tasks
  • TaskCache
  • .job
  • Rust → WebAssembly

Drop the Tasks folder, the SOFTWARE hive, or a triage ZIP

Task XML files from C:\Windows\System32\Tasks, legacy .job files from C:\Windows\Tasks and the SOFTWARE hive (TaskCache). Add both the folder and the hive: the interesting findings come from comparing them. KAPE and Velociraptor collections work as-is.

A synthetic collection from a fictional intrusion — no real data, inert placeholder commands. Tip: sort by severity, then open \SyncBackup and center the time range on it (±1 h).

100% client-side: files are parsed by WebAssembly in your browser and never uploaded.

How to get your data

Full acquisition guide

You need two things from the machine: the Tasks folder (task XML files, plus legacy .job files) and the SOFTWARE registry hive, which holds the TaskCache. Collect both, then drop the folder or ZIP here.

  1. Collect the Tasks folder and the SOFTWARE hive
  2. Drop the folder or ZIP here
  3. Parsed in your browser, never uploaded

Paste into Windows PowerShell run as administrator. It copies both Tasks folders and saves a consistent copy of the SOFTWARE hive with reg save (which includes changes still pending in the transaction logs), into C:\triage.

PowerShell · Admin
New-Item -ItemType Directory -Force -Path C:\triage\Windows\System32\config | Out-Null
robocopy C:\Windows\System32\Tasks C:\triage\Windows\System32\Tasks /E /B /R:0 /W:0 /NP /NDL /NFL
robocopy C:\Windows\Tasks C:\triage\Windows\Tasks *.job /B /R:0 /W:0 /NP /NDL /NFL
reg save HKLM\SOFTWARE C:\triage\Windows\System32\config\SOFTWARE /y

Result: C:\triage\Windows\System32\Tasks, C:\triage\Windows\Tasks and C:\triage\Windows\System32\config\SOFTWARE — the same layout as a disk, so the tool matches files and registry per machine. Drop the C:\triage folder here.

Analysing on another machine? Pack it into one ZIP with the tar.exe built into Windows 10 1803 and later (a ZIP made with Compress-Archive works too):

PowerShell / cmd
tar -a -c -f C:\triage\tasks.zip -C C:\triage Windows

Gotchas

  • Copy the whole Tasks folder, not only the tasks you suspect: "registry only" (deleted XML) can only be flagged when the folder is complete.
  • A plain copy of SOFTWARE fails while Windows runs, and some tools return a file full of zeros: use reg save, KAPE, Velociraptor or a raw copy with its .LOG1/.LOG2 files.
  • XML dates and trigger times are local time with no zone. The tool infers the offset from TaskCache times; note the machine's time zone anyway.

What are Windows scheduled tasks?

Task Scheduler runs programs at boot, at logon, on a timetable, on an event or when the machine is idle. Windows ships with hundreds of tasks of its own, and software installers add more. It is also one of the most common ways attackers keep access to a machine (MITRE ATT&CK T1053.005).

Every task exists in two places: an XML definition on disk and a cache in the SOFTWARE registry hive that Task Scheduler actually loads. Comparing the two is how you find tasks that were hidden, tampered with or had their files deleted.

Where the evidence is stored

  • C:\Windows\System32\Tasks\ — one XML file per task (UTF-16LE, no extension): author, registration date, triggers, the account it runs as, settings, and the actions (command line, COM handler).
  • SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache — Tree (task paths with Id, Index and SD values) and Tasks\{GUID} (Path, Hash, Actions, Triggers and DynamicInfo with creation and last-run FILETIMEs).
  • C:\Windows\Tasks\*.job — legacy Task Scheduler 1.0 jobs: application, parameters, author, last run time.
  • Related logs (not parsed here): Security event IDs 4698–4702 when object-access auditing is on, and Microsoft-Windows-TaskScheduler/Operational (106 registered, 140 updated, 141 deleted, 200/201 action started/completed).

What this tool checks

  • Hidden tasks: a TaskCache Tree entry without its SD value (the "Tarrask" technique) — invisible to schtasks and the console, still running.
  • Deleted or planted files: tasks registered without an XML file, and XML files with no registration; XML files edited after registration (TaskCache hash) and registry actions that differ from the file.
  • Suspicious content: encoded PowerShell (decoded for you), LOLBins, commands in user-writable or network paths, SYSTEM or highest privileges for non-Microsoft tasks, hidden non-Microsoft tasks, random-looking names and recently registered tasks.
  • Times: registration date, TaskCache creation, last run and last successful run, trigger start boundaries and registry key last-write times, on one filterable timeline.

Limitations

  • Registry transaction logs are not replayed: a dirty hive is flagged, but changes still in SOFTWARE.LOG1/LOG2 are missing.
  • TaskCache binary values (DynamicInfo, Actions, Triggers) are undocumented; their layouts come from public reverse engineering. Only the Triggers header and principal are decoded, not every trigger record.
  • XML dates, trigger times and .job times are local time without a zone; the offset is inferred when possible, and shown.
  • Deleted registry keys and deleted XML files are not carved; the event logs and volume shadow copies are the places to look for those.

How to get the files

  • Collect C:\Windows\System32\Tasks (and C:\Windows\Tasks) plus the SOFTWARE hive with KAPE (ScheduledTasks + RegistryHivesSystem), Velociraptor (Windows.Triage.Targets) or reg save and a copy of the folder.
  • Keep the folder structure (…\Windows\System32\Tasks, …\Windows\System32\config\SOFTWARE) so tasks are matched with the right hive when a ZIP holds several machines.
  • Collect the complete Tasks folder: missing XML files are only flagged when most registered tasks have theirs.

FAQ

Are my files uploaded anywhere?

No. The parser — including its registry and XML readers — is Rust compiled to WebAssembly and runs in a Web Worker in your browser. There is no upload endpoint.

How does it find hidden (Tarrask) tasks?

Task Scheduler lists a task only if its TaskCache\Tree key has an SD (security descriptor) value. Malware with SYSTEM rights can delete that value: the task disappears from schtasks and the console but keeps running. The tool flags every Tree key that has a task Id but no SD, and shows the key's last-write time.

Why do I need both the Tasks folder and the SOFTWARE hive?

Each tells half the story. The XML file is the readable definition; the TaskCache is what Task Scheduler actually loads. Tasks registered with no XML file, files that were never registered, XML edited after registration and registry actions that differ from the file only show up when both are compared.

Why are the times shifted?

Windows writes the registration date and trigger times in task XML as local time without a time zone, while TaskCache times are UTC. The tool infers the machine's offset by comparing the two for the same tasks, and you can set it yourself.

Is a flagged task malicious?

Not necessarily. Findings are pointers for triage: third-party updaters run as SYSTEM from ProgramData, some management tools use encoded PowerShell. Read the explanation on each finding and corroborate with other artifacts.

Step by step: load task XML, .job files and the SOFTWARE hive into a free in-browser parser, read hidden and registry-only tasks, fix time zones and export. With a fictional case.
A practical checklist to spot malicious scheduled tasks: user-writable paths, encoded PowerShell, LOLBins, SYSTEM principals, random names, hidden tasks and XML/registry mismatches.
How Tarrask hid scheduled tasks by deleting the TaskCache SD value, the newer deny-ACL and Index variants, and how to find hidden tasks offline from the SOFTWARE hive.