Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
FreeUnreviewedSigmahighv1
windows-registry-new-taskcache-entry-created-by-unusual-process-image-4720b7df
title: "Windows Registry: New TaskCache entry created by unusual process image"
id: 372bc13a-b0b0-4a63-a612-3d710a7a9bb0
status: test
description: This rule flags registry writes that create a new entry under the TaskCache path in Schedule. It is suspicious because attackers can tamper with or establish scheduled task-related cache artifacts to persist or execute malicious activity. Detection relies on registry set telemetry matching the TargetObject under TaskCache while excluding changes made by several known Windows and common application processes.
references:
- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
- https://labs.f-secure.com/blog/scheduled-task-tampering/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_taskcache_entry.yml
author: Syed Hasan (@syedhasan009), Huntrule Team
date: 2021-06-18
modified: 2025-10-22
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.t1053
- attack.t1053.005
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\
filter_main_empty:
Details: (Empty)
filter_main_null:
Details: null
filter_main_other:
TargetObject|contains:
- Microsoft\Windows\UpdateOrchestrator
- Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask\Index
- Microsoft\Windows\Flighting\OneSettings\RefreshCache\Index
filter_main_mousocoreworker:
Image|endswith: C:\Windows\System32\MoUsoCoreWorker.exe
filter_main_services:
Image|endswith: C:\Windows\System32\services.exe
filter_main_tiworker:
Image|startswith: C:\Windows\
Image|endswith: \TiWorker.exe
filter_main_svchost:
Image: C:\WINDOWS\system32\svchost.exe
filter_main_ngen:
Image|startswith: C:\Windows\Microsoft.NET\Framework
Image|endswith: \ngen.exe
TargetObject|contains:
- \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B66B135D-DA06-4FC4-95F8-7458E1D10129}
- \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\.NET Framework\.NET Framework NGEN
filter_main_office:
Image:
- C:\Program Files\Microsoft Office\root\Integration\Integrator.exe
- C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe
- C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
- C:\Program Files (x86)\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
filter_main_msiexec:
Image: C:\Windows\System32\msiexec.exe
filter_main_explorer:
Image: C:\Windows\explorer.exe
TargetObject|contains: \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PLA\Server Manager Performance Monitor\
filter_main_system:
Image: System
filter_main_runtimebroker:
Image: C:\Windows\System32\RuntimeBroker.exe
filter_optional_dropbox_updater:
Image:
- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
- C:\Program Files\Dropbox\Update\DropboxUpdate.exe
filter_optional_edge:
Image|endswith:
- C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
- C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
filter_optional_onedrive:
Image|endswith:
- C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
- C:\Program Files\Microsoft OneDrive\OneDrive.exe
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 4720b7df-40c3-48fd-bbdf-fd4b3c464f0d
type: derived
What it detects
This rule flags registry writes that create a new entry under the TaskCache path in Schedule. It is suspicious because attackers can tamper with or establish scheduled task-related cache artifacts to persist or execute malicious activity. Detection relies on registry set telemetry matching the TargetObject under TaskCache while excluding changes made by several known Windows and common application processes.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.