Diving into Hidden Scheduled Tasks
ID: 3629bebc-9e5b-5af1-8f90-e6626a9d8b73
STIX ID: report--3629bebc-9e5b-5af1-8f90-e6626a9d8b73
Feed Name: Binary Defense Blog
**Executive Summary:** This report expands on Microsoft’s findings about the ‘Tarrask’ malware technique that hides scheduled tasks by removing or altering the Security Descriptor (SD) registry value; ARC Labs demonstrates additional evasion methods (importing tasks, creating registry keys without SD, and setting deny SDDL entries) that can bypass Event Log and registry-auditing telemetry on Windows 10/11 and provides detection guidance, Sysmon rules, and a PowerShell hunt script to identify tampered or stealthy scheduled tasks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
