Task Scheduler Files

Task Scheduler Files are XML files that provide information regarding scheduled tasks on an endpoint. These files are created when a new task is scheduled on the endpoint. This artifact is similar to and replaces .job files on Windows XP, but provides more information.

Analysis Value

Command Line Optionschevron-rightFirst Executedchevron-rightLast Executedchevron-rightExecution Accountchevron-rightEvidence of Executionchevron-rightFile Pathchevron-rightSource Identificationchevron-right

Operating System Availability

Major Version
Support
Major Version
Support

Windows 11

βœ…

Server 2019

βœ…

Windows 10

βœ…

Server 2016

βœ…

Windows 8

βœ…

Server 2012

βœ…

Windows 7

βœ…

Server 2008

βœ…

Windows Vista

βœ…

Server 2003

❌

Windows XP

❌

Artifact Location(s)

  • %SystemRoot%\System32\Tasks for tasks scheduled by 64-bit processes

  • %SystemRoot%\SysWOW64\Tasks for tasks scheduled by 32-bit processes

Artifact Interpretation

XML Path
Interpretation

Task/Registration Info/Date

Date the task was scheduled

Task/Registration Info/Author

Author of the task. Can be local or remote.

Task/Triggers

Triggers for the scheduled task

Task/Actions

Action taken by the scheduled task

Task/Principals

Authentication used for the task during execution

Analysis Tips

circle-check

Remote Scheduled Tasks

Last updated