TaskCache · field notes
Blog
Articles, guides, and updates.
Step by step: load task XML, .job files and the SOFTWARE hive into a free in-browser parser, read hidden and registry-only tasks, fix time zones and export. With a fictional case.
A practical checklist to spot malicious scheduled tasks: user-writable paths, encoded PowerShell, LOLBins, SYSTEM principals, random names, hidden tasks and XML/registry mismatches.
How Tarrask hid scheduled tasks by deleting the TaskCache SD value, the newer deny-ACL and Index variants, and how to find hidden tasks offline from the SOFTWARE hive.
How to read legacy .job files: the MS-TSCH fixed and variable sections, triggers, the local-time last run SYSTEMTIME, and when .job files still appear on modern Windows.
What the TaskCache key in the SOFTWARE hive stores for each scheduled task: Tree Id/Index/SD, Tasks values, DynamicInfo run times, Actions and Triggers blobs, and the Hash.
Read a Task Scheduler XML file like an investigator: RegistrationInfo, Triggers, Principals, Settings and Actions, and the zoneless local times in Date and StartBoundary.
Every place Windows keeps scheduled tasks: System32\Tasks, SysWOW64\Tasks, C:\Windows\Tasks and TaskCache, plus how to collect them with KAPE or Velociraptor.
Scheduled task forensics end to end: task XML files, the TaskCache registry key, legacy .job files and event logs, and how to correlate them in a case.