Skip to content

A–Z

Glossary

Plain-language definitions of the scheduled-task forensics terms used across the blog.

TaskCache Hash value
The integrity hash stored in TaskCache\Tasks\{GUID}\Hash, observed as SHA-256 of the task XML without its byte order mark on current Windows.
Encoded PowerShell
A PowerShell command passed as Base64 of UTF-16LE text with -EncodedCommand, often used to hide the real script in scheduled task arguments.
LOLBin
A legitimate, usually Microsoft-signed binary that attackers use to run or fetch code, such as rundll32, regsvr32, mshta or certutil.
schtasks.exe
The built-in Windows command-line tool to create, query, change, run and delete scheduled tasks, the replacement for the deprecated at.exe.
taskhostw.exe
The Windows process that hosts DLL-based scheduled tasks (COM handler actions), started by the Task Scheduler service.
RunLevel
The Principal element that decides whether a scheduled task runs with the account's least privileges or with its highest available (administrator) token.
StartBoundary
The trigger element giving the date and time from which a scheduled task trigger is active, usually stored as local time with no UTC offset.
COM handler action
A scheduled task action that runs a COM object identified by a CLSID instead of an executable, usually a DLL hosted by taskhostw.exe.
LogonType S4U
A scheduled task principal setting that runs the task as a user without storing the password, with no access to network resources by that user's credentials.
DynamicInfo
A binary value in TaskCache\Tasks\{GUID} holding a task's creation, last run and last successful run FILETIMEs and its last result code.
.job file
The binary Task Scheduler 1.0 task format stored in C:\Windows\Tasks, specified by Microsoft in MS-TSCH.
Security descriptor (SD value)
The binary SD value under TaskCache\Tree that sets who can read and change a scheduled task; deleting it hides the task from schtasks and the console.
Tarrask
Malware described by Microsoft in April 2022 that hid scheduled tasks by deleting their SD value in the TaskCache registry key.
Task Scheduler XML schema
The Microsoft XML schema that defines scheduled task files: RegistrationInfo, Triggers, Principals, Settings, Data and Actions elements.
TaskCache
The registry key in the SOFTWARE hive where the Task Scheduler service keeps its copy of every registered task: Tree, Tasks and category subkeys.