Windows Registry: New TaskCache entry created by unusual process image

Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.

FreeUnreviewedSigmahighv1
title: "Windows Registry: New TaskCache entry created by unusual process image"
id: 372bc13a-b0b0-4a63-a612-3d710a7a9bb0
status: test
description: This rule flags registry writes that create a new entry under the TaskCache path in Schedule. It is suspicious because attackers can tamper with or establish scheduled task-related cache artifacts to persist or execute malicious activity. Detection relies on registry set telemetry matching the TargetObject under TaskCache while excluding changes made by several known Windows and common application processes.
references:
  - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
  - https://labs.f-secure.com/blog/scheduled-task-tampering/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_taskcache_entry.yml
author: Syed Hasan (@syedhasan009), Huntrule Team
date: 2021-06-18
modified: 2025-10-22
tags:
  - attack.privilege-escalation
  - attack.execution
  - attack.persistence
  - attack.t1053
  - attack.t1053.005
logsource:
  category: registry_set
  product: windows
detection:
  selection:
    TargetObject|contains: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\
  filter_main_empty:
    Details: (Empty)
  filter_main_null:
    Details: null
  filter_main_other:
    TargetObject|contains:
      - Microsoft\Windows\UpdateOrchestrator
      - Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask\Index
      - Microsoft\Windows\Flighting\OneSettings\RefreshCache\Index
  filter_main_mousocoreworker:
    Image|endswith: C:\Windows\System32\MoUsoCoreWorker.exe
  filter_main_services:
    Image|endswith: C:\Windows\System32\services.exe
  filter_main_tiworker:
    Image|startswith: C:\Windows\
    Image|endswith: \TiWorker.exe
  filter_main_svchost:
    Image: C:\WINDOWS\system32\svchost.exe
  filter_main_ngen:
    Image|startswith: C:\Windows\Microsoft.NET\Framework
    Image|endswith: \ngen.exe
    TargetObject|contains:
      - \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B66B135D-DA06-4FC4-95F8-7458E1D10129}
      - \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\.NET Framework\.NET Framework NGEN
  filter_main_office:
    Image:
      - C:\Program Files\Microsoft Office\root\Integration\Integrator.exe
      - C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe
      - C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
      - C:\Program Files (x86)\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe
  filter_main_msiexec:
    Image: C:\Windows\System32\msiexec.exe
  filter_main_explorer:
    Image: C:\Windows\explorer.exe
    TargetObject|contains: \Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PLA\Server Manager Performance Monitor\
  filter_main_system:
    Image: System
  filter_main_runtimebroker:
    Image: C:\Windows\System32\RuntimeBroker.exe
  filter_optional_dropbox_updater:
    Image:
      - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
      - C:\Program Files\Dropbox\Update\DropboxUpdate.exe
  filter_optional_edge:
    Image|endswith:
      - C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
      - C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
  filter_optional_onedrive:
    Image|endswith:
      - C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
      - C:\Program Files\Microsoft OneDrive\OneDrive.exe
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 4720b7df-40c3-48fd-bbdf-fd4b3c464f0d
    type: derived

What it detects

This rule flags registry writes that create a new entry under the TaskCache path in Schedule. It is suspicious because attackers can tamper with or establish scheduled task-related cache artifacts to persist or execute malicious activity. Detection relies on registry set telemetry matching the TargetObject under TaskCache while excluding changes made by several known Windows and common application processes.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.