From ea5b88c056248b796bdefbb2f3f443483d60359e Mon Sep 17 00:00:00 2001 From: jason taylor Date: Wed, 20 Nov 2024 09:47:50 -0500 Subject: [PATCH] minor spelling and trailing space update --- .../library/windows/task_scheduler_service.md | 238 +++++++++--------- 1 file changed, 119 insertions(+), 119 deletions(-) diff --git a/docs/library/windows/task_scheduler_service.md b/docs/library/windows/task_scheduler_service.md index e8a9df4f..74895302 100644 --- a/docs/library/windows/task_scheduler_service.md +++ b/docs/library/windows/task_scheduler_service.md @@ -27,16 +27,16 @@ Offset : 510656 ServiceName : Schedule ServiceDisplayName : Task Scheduler IsServiceRunning : True -Endpoints : {[86d35949-83c9-4044-b424-db363231fd0c, 1.0] ncalrpc:[LRPC-4803de23b17986468a], [86d35949-83c9-4044-b424-db363231fd0c, 1.0] ncalrpc:[ubpmtaskhostchannel], +Endpoints : {[86d35949-83c9-4044-b424-db363231fd0c, 1.0] ncalrpc:[LRPC-4803de23b17986468a], [86d35949-83c9-4044-b424-db363231fd0c, 1.0] ncalrpc:[ubpmtaskhostchannel], [86d35949-83c9-4044-b424-db363231fd0c, 1.0] ncalrpc:[LRPC-83a142d94b8e74a91a]} EndpointCount : 3 -Client : False +Client : False ``` ### RPC Clients * taskcomp.dll * taskschd.dll -* wmicmiplugin.dll +* wmicmiplugin.dll ### RPC Methods @@ -65,8 +65,8 @@ ComplexTypes : {Struct_0, Struct_1, Struct_2} FilePath : C:\Windows\System32\taskcomp.dll Name : taskcomp.dll Offset : 322256 -ServiceName : -ServiceDisplayName : +ServiceName : +ServiceDisplayName : IsServiceRunning : False Endpoints : {[1ff70682-0a51-30e8-076d-740be8cee98b, 1.0] ncalrpc:[LRPC-b858137bbb082a0e8d]} EndpointCount : 1 @@ -104,7 +104,7 @@ Client : False ## Interact with Task Scheduler Remotely -### Powershell - Schedule.Service COM Object +### Powershell - Schedule.Service COM Object ```Powershell # connect to Task Scheduler: $service = New-Object -ComObject Schedule.Service @@ -145,43 +145,43 @@ $NewTask.stop(0) * EventID 4702 (Target): A Scheduled Task Was updated ```xml -- - - - - 4702 - 1 - 0 - 12804 - 0 - 0x8020000000000000 - - 2292968 - - - Security - WORKSTATION6.theshire.local - - - - - S-1-5-21-3786818125-2382361537-3207726629-1104 - pgustavo - THESHIRE - 0x9ac216f - \Ward0g - 2020-12-16T08:09:21.4521839 THESHIRE\sbeavers Que pasa \Ward0g true S-1-5-21-3786818125-2382361537-3207726629-1106 InteractiveToken LeastPrivilege IgnoreNew true true true false false true false true true false false false PT72H 7 powershell -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBpAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAHIAUwBwAt..... - 0 - 0 - 0 - 0 - WORKSTATION6.theshire.local - +- + - + + 4702 + 1 + 0 + 12804 + 0 + 0x8020000000000000 + + 2292968 + + + Security + WORKSTATION6.theshire.local + + + - + S-1-5-21-3786818125-2382361537-3207726629-1104 + pgustavo + THESHIRE + 0x9ac216f + \Ward0g + 2020-12-16T08:09:21.4521839 THESHIRE\sbeavers Que pasa \Ward0g true S-1-5-21-3786818125-2382361537-3207726629-1106 InteractiveToken LeastPrivilege IgnoreNew true true true false false true false true true false false false PT72H 7 powershell -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBpAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAHIAUwBwAt..... + 0 + 0 + 0 + 0 + WORKSTATION6.theshire.local + ``` * EventID 4688 (Target): A New Process Has been created ### Microsoft-Windows-TaskScheduler/Operational Logs -* EventID 140: Task Rergistration Updated +* EventID 140: Task Registration Updated * EventID 100: Task Started * EventID 201: Action Completed * EventID 201: Task Completed @@ -193,94 +193,94 @@ $NewTask.stop(0) * EventID 1: ProcessCreate (When Task is stopped) ```xml -- - - - - 1 - 5 - 4 - 1 - 0 - 0x8000000000000000 - - 9090341 - - - Microsoft-Windows-Sysmon/Operational - WORKSTATION6.theshire.local - - - - - - - 2020-12-16 17:23:48.185 - {649442b8-42a4-5fda-af62-000000000600} - 2836 - C:\Windows\System32\taskhostw.exe - 10.0.18362.1237 (WinBuild.160101.0800) - Host Process for Windows Tasks - Microsoft® Windows® Operating System - Microsoft Corporation - taskhostw.exe - taskhostw.exe C:\windows\System32\WindowsPowerShell\v1.0\powershell.EXE -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBpAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAHIAUwBpAE8AbgAuAE0AYQBqAE8AcgAgAC0AZwBFACAAMwApAHsAJAA4... - C:\windows\system32\ - THESHIRE\sbeavers - {649442b8-783d-5fd2-c316-e00000000000} - 0xe016c3 - 2 - Medium - SHA1=6630F5E1A1ACC1C8E95A7958542DD87D0735D99B,MD5=52071D9553A92A12F22DDDF6DB6F9643,SHA256=ABCA3394728697205DEAD7C9B7B9076CDD28BEE84E7A3C84514478BC033E531A,IMPHASH=9CB27CAED52CB0AFFB32788922A0D083 - {649442b8-52dc-5fd1-3600-000000000600} - 2220 - C:\Windows\System32\svchost.exe - C:\windows\system32\svchost.exe -k netsvcs -p -s Schedule - +- + - + + 1 + 5 + 4 + 1 + 0 + 0x8000000000000000 + + 9090341 + + + Microsoft-Windows-Sysmon/Operational + WORKSTATION6.theshire.local + + + - + - + 2020-12-16 17:23:48.185 + {649442b8-42a4-5fda-af62-000000000600} + 2836 + C:\Windows\System32\taskhostw.exe + 10.0.18362.1237 (WinBuild.160101.0800) + Host Process for Windows Tasks + Microsoft® Windows® Operating System + Microsoft Corporation + taskhostw.exe + taskhostw.exe C:\windows\System32\WindowsPowerShell\v1.0\powershell.EXE -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBpAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAHIAUwBpAE8AbgAuAE0AYQBqAE8AcgAgAC0AZwBFACAAMwApAHsAJAA4... + C:\windows\system32\ + THESHIRE\sbeavers + {649442b8-783d-5fd2-c316-e00000000000} + 0xe016c3 + 2 + Medium + SHA1=6630F5E1A1ACC1C8E95A7958542DD87D0735D99B,MD5=52071D9553A92A12F22DDDF6DB6F9643,SHA256=ABCA3394728697205DEAD7C9B7B9076CDD28BEE84E7A3C84514478BC033E531A,IMPHASH=9CB27CAED52CB0AFFB32788922A0D083 + {649442b8-52dc-5fd1-3600-000000000600} + 2220 + C:\Windows\System32\svchost.exe + C:\windows\system32\svchost.exe -k netsvcs -p -s Schedule + ``` * EventID 1: ProcessCreate (Execution when task is forced to execute or task is updated) ```xml -- - - - - 1 - 5 - 4 - 1 - 0 - 0x8000000000000000 - - 9103725 - - - Microsoft-Windows-Sysmon/Operational - WORKSTATION6.theshire.local - - - - - - - 2020-12-16 17:40:05.997 - {649442b8-4675-5fda-d962-000000000600} - 6840 - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - 10.0.18362.1 (WinBuild.160101.0800) - Windows PowerShell - Microsoft® Windows® Operating System - Microsoft Corporation - PowerShell.EXE - C:\windows\System32\WindowsPowerShell\v1.0\powershell.EXE -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBpAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAHIAUwBpAE8AbgAuAE0AYQBqAE8AcgAgAC0AZwBFACAAMwAp... - C:\windows\system32\ - THESHIRE\sbeavers - {649442b8-783d-5fd2-c316-e00000000000} - 0xe016c3 - 2 - Medium - SHA1=36C5D12033B2EAF251BAE61C00690FFB17FDDC87,MD5=CDA48FC75952AD12D99E526D0B6BF70A,SHA256=908B64B1971A979C7E3E8CE4621945CBA84854CB98D76367B791A6E22B5F6D53,IMPHASH=A7CEFACDDA74B13CD330390769752481 - {649442b8-52dc-5fd1-3600-000000000600} - 2220 - C:\Windows\System32\svchost.exe - C:\windows\system32\svchost.exe -k netsvcs -p -s Schedule - +- + - + + 1 + 5 + 4 + 1 + 0 + 0x8000000000000000 + + 9103725 + + + Microsoft-Windows-Sysmon/Operational + WORKSTATION6.theshire.local + + + - + - + 2020-12-16 17:40:05.997 + {649442b8-4675-5fda-d962-000000000600} + 6840 + C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe + 10.0.18362.1 (WinBuild.160101.0800) + Windows PowerShell + Microsoft® Windows® Operating System + Microsoft Corporation + PowerShell.EXE + C:\windows\System32\WindowsPowerShell\v1.0\powershell.EXE -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAFIAUwBpAE8ATgBUAGEAQgBMAGUALgBQAFMAVgBlAHIAUwBpAE8AbgAuAE0AYQBqAE8AcgAgAC0AZwBFACAAMwAp... + C:\windows\system32\ + THESHIRE\sbeavers + {649442b8-783d-5fd2-c316-e00000000000} + 0xe016c3 + 2 + Medium + SHA1=36C5D12033B2EAF251BAE61C00690FFB17FDDC87,MD5=CDA48FC75952AD12D99E526D0B6BF70A,SHA256=908B64B1971A979C7E3E8CE4621945CBA84854CB98D76367B791A6E22B5F6D53,IMPHASH=A7CEFACDDA74B13CD330390769752481 + {649442b8-52dc-5fd1-3600-000000000600} + 2220 + C:\Windows\System32\svchost.exe + C:\windows\system32\svchost.exe -k netsvcs -p -s Schedule + ```