Where Are Scheduled Tasks Stored? Locations and Acquisition
Every place Windows keeps scheduled tasks: System32\Tasks, SysWOW64\Tasks, C:\Windows\Tasks and TaskCache, plus how to collect them with KAPE or Velociraptor.
TL;DR. Collect four things: C:\Windows\System32\Tasks (recursive), C:\Windows\SysWOW64\Tasks, C:\Windows\Tasks, and the SOFTWARE hive with SOFTWARE.LOG1 and SOFTWARE.LOG2. Add Security.evtx and the TaskScheduler/Operational log. KAPE --target ScheduledTasks,RegistryHivesSystem or Velociraptor's Windows.Triage.Targets with the same two targets does it in one pass. Keep the original paths: the folder structure under Tasks is the task path.
This article is the acquisition companion to the complete guide to scheduled task forensics.
The locations, by artifact
| Artifact | Path | Format | Windows versions |
|---|---|---|---|
| Task XML | C:\Windows\System32\Tasks\ and subfolders | Extensionless XML, usually UTF-16LE with a byte order mark | Vista and later |
| Task XML (WOW64) | C:\Windows\SysWOW64\Tasks\ | Same | 64-bit systems; often empty, collect anyway |
| Legacy jobs | C:\Windows\Tasks\*.job | Binary .job, MS-TSCH | Primary store up to XP / 2003; legacy only afterwards |
| Legacy scheduler log | C:\Windows\SchedLgU.txt | Text | Mostly older systems |
| TaskCache | C:\Windows\System32\config\SOFTWARE, key Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache | Registry hive | Vista and later |
| Hive transaction logs | C:\Windows\System32\config\SOFTWARE.LOG1, SOFTWARE.LOG2 | Registry log | Vista and later |
| Event logs | C:\Windows\System32\winevt\Logs\Security.evtx, Microsoft-Windows-TaskScheduler%4Operational.evtx | EVTX | Vista and later |
The KapeFiles ScheduledTasks target lists the same XML folders, C:\Windows\Tasks\*.job, SchedLgU.txt, the Windows.old equivalents, and the PowerShell ScheduledJobs folders under each profile. If the system was upgraded in place, C:\Windows.old can hold task definitions from before the upgrade: collect it when present.
How the XML folder is organised
Every folder in the Task Scheduler Library is a real folder on disk. A task registered as \Microsoft\Windows\Defrag\ScheduledDefrag is the file C:\Windows\System32\Tasks\Microsoft\Windows\Defrag\ScheduledDefrag. The file has no extension, and its <URI> element normally repeats the same path. That path is also the key name under TaskCache\Tree, which is how the XML and the registry are paired.
Tasks at the root (C:\Windows\System32\Tasks\<name>) deserve attention: Microsoft's monitoring guidance for event 4698 notes that manually created and malicious tasks are often placed in the root node. Many legitimate third-party updaters also live there, so root placement is a sorting key, not a finding.
TaskCache in the SOFTWARE hive
On a live system the key is HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache. Offline, it is inside the file C:\Windows\System32\config\SOFTWARE. Its subkeys are Tree, Tasks, Boot, Logon, Plain and Maintenance (cyber.wtf). What each value means is covered in TaskCache registry forensics.
Why the transaction logs matter
Since Windows 8.1, registry changes are written to the hive's transaction logs (.LOG1, .LOG2) first and flushed to the primary file lazily (Maxim Suhanov's registry format notes). A copy of SOFTWARE taken from a running machine is therefore often dirty: its header sequence numbers do not match, and the newest changes exist only in the logs. For scheduled tasks that is exactly the data you want: a task registered ten minutes before collection, or an SD value deleted to hide it, may not yet be in the primary file.
Collect the logs with the hive. Then replay them with a tool that supports it before relying on "absence" in TaskCache. The Scheduled Tasks Parser reads the primary hive and warns when it is dirty; it does not replay the logs itself, so a dirty warning means "re-check this hive with a log-aware tool".
Collection options
KAPE
kape.exe --tsource C: --tdest C:\triage\kape --target ScheduledTasks,RegistryHivesSystem
ScheduledTasks brings the task folders, .job files and SchedLgU.txt; RegistryHivesSystem brings SOFTWARE with SOFTWARE.LOG*, plus the other system hives. Add an event log target if you also want the EVTX files. KAPE reads locked files through raw disk access, so the hive copy is consistent with its logs at collection time.
Velociraptor
Run the Windows.Triage.Targets artifact (GUI hunt or offline collector) with the ScheduledTasks and RegistryHivesSystem targets selected. The artifact is built from the KapeFiles rules (Velociraptor triage documentation), so the file set matches KAPE's. The resulting ZIP can be dropped as-is into the parser: it handles Velociraptor's percent-encoded paths and backslash entry names.
Built-in commands, when nothing else is available
From an elevated prompt on the live system:
reg save HKLM\SOFTWARE C:\triage\SOFTWARE /y
robocopy C:\Windows\System32\Tasks C:\triage\Tasks /E
robocopy C:\Windows\SysWOW64\Tasks C:\triage\SysWOW64Tasks /E
robocopy C:\Windows\Tasks C:\triage\LegacyTasks /E
reg save produces a clean, self-consistent hive (no separate logs needed), but it runs through the registry API, so it is an action on the live system: note the time in your case log. Robocopy preserves the folder tree, which you need for task paths. This method is fine for triage; for evidence you plan to present, prefer a forensic image or a raw-access collector.
Disk images
Mount the image read-only and export the same paths. Also look for Volume Shadow Copies: older versions of SOFTWARE and of the Tasks folder can show when a task appeared or what it looked like before it was altered.
Access and hiding pitfalls on live systems
- Querying with
schtasks /queryor the console will not list a task whoseSDvalue was removed, and may not list one with a restrictive descriptor. That is the whole point of the Tarrask technique. File and hive collection bypasses the problem. - The XML files are readable by administrators, but some are ACL-restricted. Raw-access collectors avoid access-denied gaps; a plain
copymay silently skip files. - Do not open the task in the console "to have a look": saving from the console rewrites the XML and the TaskCache entry.
After collection
Hash everything, keep the original tree, and write down the machine's time zone if you can get it (from the SYSTEM hive's TimeZoneInformation key or your collection notes). You will need it for zoneless XML times, as explained in task XML anatomy. Then parse: how to analyze scheduled tasks in your browser.
FAQ
Where are scheduled task files located in Windows 10 and 11?
Task definitions are extensionless XML files under C:\Windows\System32\Tasks, in subfolders that mirror the task path. The registry copy is in the SOFTWARE hive under Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache. Legacy .job files, if any, are in C:\Windows\Tasks.
Do I need the registry transaction logs?
Yes. A SOFTWARE hive copied from a running system is often dirty: recent changes, such as a freshly registered or hidden task, may still be in SOFTWARE.LOG1 or SOFTWARE.LOG2. Collect them with the hive and replay them before drawing conclusions.
Which KAPE targets collect scheduled tasks?
ScheduledTasks collects the XML folders, .job files and SchedLgU.txt; RegistryHivesSystem collects the SOFTWARE hive and its transaction logs. Use both.