Posts tagged: #dfir
Step by step: load task XML, .job files and the SOFTWARE hive into a free in-browser parser, read hidden and registry-only tasks, fix time zones and export. With a fictional case.
A practical checklist to spot malicious scheduled tasks: user-writable paths, encoded PowerShell, LOLBins, SYSTEM principals, random names, hidden tasks and XML/registry mismatches.
How to read legacy .job files: the MS-TSCH fixed and variable sections, triggers, the local-time last run SYSTEMTIME, and when .job files still appear on modern Windows.
What the TaskCache key in the SOFTWARE hive stores for each scheduled task: Tree Id/Index/SD, Tasks values, DynamicInfo run times, Actions and Triggers blobs, and the Hash.
Read a Task Scheduler XML file like an investigator: RegistrationInfo, Triggers, Principals, Settings and Actions, and the zoneless local times in Date and StartBoundary.
Scheduled task forensics end to end: task XML files, the TaskCache registry key, legacy .job files and event logs, and how to correlate them in a case.