logo

Diving into Hidden Scheduled Tasks

ID: 3629bebc-9e5b-5af1-8f90-e6626a9d8b73

STIX ID: report--3629bebc-9e5b-5af1-8f90-e6626a9d8b73

Feed Name: Binary Defense Blog

Threat Score
65/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

**Executive Summary:** This report expands on Microsoft’s findings about the ‘Tarrask’ malware technique that hides scheduled tasks by removing or altering the Security Descriptor (SD) registry value; ARC Labs demonstrates additional evasion methods (importing tasks, creating registry keys without SD, and setting deny SDDL entries) that can bypass Event Log and registry-auditing telemetry on Windows 10/11 and provides detection guidance, Sysmon rules, and a PowerShell hunt script to identify tampered or stealthy scheduled tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.