Skip to content

Where Are Scheduled Tasks Stored? Locations and Acquisition

Every place Windows keeps scheduled tasks: System32\Tasks, SysWOW64\Tasks, C:\Windows\Tasks and TaskCache, plus how to collect them with KAPE or Velociraptor.

Published on 5 min read

TL;DR. Collect four things: C:\Windows\System32\Tasks (recursive), C:\Windows\SysWOW64\Tasks, C:\Windows\Tasks, and the SOFTWARE hive with SOFTWARE.LOG1 and SOFTWARE.LOG2. Add Security.evtx and the TaskScheduler/Operational log. KAPE --target ScheduledTasks,RegistryHivesSystem or Velociraptor's Windows.Triage.Targets with the same two targets does it in one pass. Keep the original paths: the folder structure under Tasks is the task path.

This article is the acquisition companion to the complete guide to scheduled task forensics.

The locations, by artifact

ArtifactPathFormatWindows versions
Task XMLC:\Windows\System32\Tasks\ and subfoldersExtensionless XML, usually UTF-16LE with a byte order markVista and later
Task XML (WOW64)C:\Windows\SysWOW64\Tasks\Same64-bit systems; often empty, collect anyway
Legacy jobsC:\Windows\Tasks\*.jobBinary .job, MS-TSCHPrimary store up to XP / 2003; legacy only afterwards
Legacy scheduler logC:\Windows\SchedLgU.txtTextMostly older systems
TaskCacheC:\Windows\System32\config\SOFTWARE, key Microsoft\Windows NT\CurrentVersion\Schedule\TaskCacheRegistry hiveVista and later
Hive transaction logsC:\Windows\System32\config\SOFTWARE.LOG1, SOFTWARE.LOG2Registry logVista and later
Event logsC:\Windows\System32\winevt\Logs\Security.evtx, Microsoft-Windows-TaskScheduler%4Operational.evtxEVTXVista and later

The KapeFiles ScheduledTasks target lists the same XML folders, C:\Windows\Tasks\*.job, SchedLgU.txt, the Windows.old equivalents, and the PowerShell ScheduledJobs folders under each profile. If the system was upgraded in place, C:\Windows.old can hold task definitions from before the upgrade: collect it when present.

How the XML folder is organised

Every folder in the Task Scheduler Library is a real folder on disk. A task registered as \Microsoft\Windows\Defrag\ScheduledDefrag is the file C:\Windows\System32\Tasks\Microsoft\Windows\Defrag\ScheduledDefrag. The file has no extension, and its <URI> element normally repeats the same path. That path is also the key name under TaskCache\Tree, which is how the XML and the registry are paired.

Tasks at the root (C:\Windows\System32\Tasks\<name>) deserve attention: Microsoft's monitoring guidance for event 4698 notes that manually created and malicious tasks are often placed in the root node. Many legitimate third-party updaters also live there, so root placement is a sorting key, not a finding.

TaskCache in the SOFTWARE hive

On a live system the key is HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache. Offline, it is inside the file C:\Windows\System32\config\SOFTWARE. Its subkeys are Tree, Tasks, Boot, Logon, Plain and Maintenance (cyber.wtf). What each value means is covered in TaskCache registry forensics.

Why the transaction logs matter

Since Windows 8.1, registry changes are written to the hive's transaction logs (.LOG1, .LOG2) first and flushed to the primary file lazily (Maxim Suhanov's registry format notes). A copy of SOFTWARE taken from a running machine is therefore often dirty: its header sequence numbers do not match, and the newest changes exist only in the logs. For scheduled tasks that is exactly the data you want: a task registered ten minutes before collection, or an SD value deleted to hide it, may not yet be in the primary file.

Collect the logs with the hive. Then replay them with a tool that supports it before relying on "absence" in TaskCache. The Scheduled Tasks Parser reads the primary hive and warns when it is dirty; it does not replay the logs itself, so a dirty warning means "re-check this hive with a log-aware tool".

Collection options

KAPE

kape.exe --tsource C: --tdest C:\triage\kape --target ScheduledTasks,RegistryHivesSystem

ScheduledTasks brings the task folders, .job files and SchedLgU.txt; RegistryHivesSystem brings SOFTWARE with SOFTWARE.LOG*, plus the other system hives. Add an event log target if you also want the EVTX files. KAPE reads locked files through raw disk access, so the hive copy is consistent with its logs at collection time.

Velociraptor

Run the Windows.Triage.Targets artifact (GUI hunt or offline collector) with the ScheduledTasks and RegistryHivesSystem targets selected. The artifact is built from the KapeFiles rules (Velociraptor triage documentation), so the file set matches KAPE's. The resulting ZIP can be dropped as-is into the parser: it handles Velociraptor's percent-encoded paths and backslash entry names.

Built-in commands, when nothing else is available

From an elevated prompt on the live system:

reg save HKLM\SOFTWARE C:\triage\SOFTWARE /y
robocopy C:\Windows\System32\Tasks C:\triage\Tasks /E
robocopy C:\Windows\SysWOW64\Tasks C:\triage\SysWOW64Tasks /E
robocopy C:\Windows\Tasks C:\triage\LegacyTasks /E

reg save produces a clean, self-consistent hive (no separate logs needed), but it runs through the registry API, so it is an action on the live system: note the time in your case log. Robocopy preserves the folder tree, which you need for task paths. This method is fine for triage; for evidence you plan to present, prefer a forensic image or a raw-access collector.

Disk images

Mount the image read-only and export the same paths. Also look for Volume Shadow Copies: older versions of SOFTWARE and of the Tasks folder can show when a task appeared or what it looked like before it was altered.

Access and hiding pitfalls on live systems

  • Querying with schtasks /query or the console will not list a task whose SD value was removed, and may not list one with a restrictive descriptor. That is the whole point of the Tarrask technique. File and hive collection bypasses the problem.
  • The XML files are readable by administrators, but some are ACL-restricted. Raw-access collectors avoid access-denied gaps; a plain copy may silently skip files.
  • Do not open the task in the console "to have a look": saving from the console rewrites the XML and the TaskCache entry.

After collection

Hash everything, keep the original tree, and write down the machine's time zone if you can get it (from the SYSTEM hive's TimeZoneInformation key or your collection notes). You will need it for zoneless XML times, as explained in task XML anatomy. Then parse: how to analyze scheduled tasks in your browser.

FAQ

Where are scheduled task files located in Windows 10 and 11?

Task definitions are extensionless XML files under C:\Windows\System32\Tasks, in subfolders that mirror the task path. The registry copy is in the SOFTWARE hive under Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache. Legacy .job files, if any, are in C:\Windows\Tasks.

Do I need the registry transaction logs?

Yes. A SOFTWARE hive copied from a running system is often dirty: recent changes, such as a freshly registered or hidden task, may still be in SOFTWARE.LOG1 or SOFTWARE.LOG2. Collect them with the hive and replay them before drawing conclusions.

Which KAPE targets collect scheduled tasks?

ScheduledTasks collects the XML folders, .job files and SchedLgU.txt; RegistryHivesSystem collects the SOFTWARE hive and its transaction logs. Use both.

Related articles

Step by step: load task XML, .job files and the SOFTWARE hive into a free in-browser parser, read hidden and registry-only tasks, fix time zones and export. With a fictional case.
A practical checklist to spot malicious scheduled tasks: user-writable paths, encoded PowerShell, LOLBins, SYSTEM principals, random names, hidden tasks and XML/registry mismatches.
How Tarrask hid scheduled tasks by deleting the TaskCache SD value, the newer deny-ACL and Index variants, and how to find hidden tasks offline from the SOFTWARE hive.