Skip to content

Glossary

Security descriptor (SD value)

The binary SD value under TaskCache\Tree that sets who can read and change a scheduled task; deleting it hides the task from schtasks and the console.

Each task key under TaskCache\Tree normally has an SD value: a self-relative Windows security descriptor, readable as an SDDL string once decoded, whose access control list decides which accounts can see and modify the task.

Removing the value makes the task invisible to schtasks /query and the Task Scheduler console while it keeps running, as Microsoft documented for Tarrask. A descriptor that denies read access has a similar effect. See Tarrask and hidden scheduled tasks.