A–Z
Glossary
Plain-language definitions of the scheduled-task forensics terms used across the blog.
- TaskCache Hash value
- The integrity hash stored in TaskCache\Tasks\{GUID}\Hash, observed as SHA-256 of the task XML without its byte order mark on current Windows.
- Encoded PowerShell
- A PowerShell command passed as Base64 of UTF-16LE text with -EncodedCommand, often used to hide the real script in scheduled task arguments.
- LOLBin
- A legitimate, usually Microsoft-signed binary that attackers use to run or fetch code, such as rundll32, regsvr32, mshta or certutil.
- schtasks.exe
- The built-in Windows command-line tool to create, query, change, run and delete scheduled tasks, the replacement for the deprecated at.exe.
- taskhostw.exe
- The Windows process that hosts DLL-based scheduled tasks (COM handler actions), started by the Task Scheduler service.
- RunLevel
- The Principal element that decides whether a scheduled task runs with the account's least privileges or with its highest available (administrator) token.
- StartBoundary
- The trigger element giving the date and time from which a scheduled task trigger is active, usually stored as local time with no UTC offset.
- COM handler action
- A scheduled task action that runs a COM object identified by a CLSID instead of an executable, usually a DLL hosted by taskhostw.exe.
- LogonType S4U
- A scheduled task principal setting that runs the task as a user without storing the password, with no access to network resources by that user's credentials.
- DynamicInfo
- A binary value in TaskCache\Tasks\{GUID} holding a task's creation, last run and last successful run FILETIMEs and its last result code.
- .job file
- The binary Task Scheduler 1.0 task format stored in C:\Windows\Tasks, specified by Microsoft in MS-TSCH.
- Security descriptor (SD value)
- The binary SD value under TaskCache\Tree that sets who can read and change a scheduled task; deleting it hides the task from schtasks and the console.
- Tarrask
- Malware described by Microsoft in April 2022 that hid scheduled tasks by deleting their SD value in the TaskCache registry key.
- Task Scheduler XML schema
- The Microsoft XML schema that defines scheduled task files: RegistrationInfo, Triggers, Principals, Settings, Data and Actions elements.
- TaskCache
- The registry key in the SOFTWARE hive where the Task Scheduler service keeps its copy of every registered task: Tree, Tasks and category subkeys.