Cyber Security News

TaskHound Tool – Detects Windows Scheduled Tasks Running with Elevated Privileges and Stored Credentials

A new open-source security tool, TaskHound, helps penetration testers and security professionals identify high-risk Windows scheduled tasks that could expose systems to attacks.

The tool automatically discovers tasks running with privileged accounts and stored credentials, making it a valuable addition to security assessments.

What Makes TaskHound Different?

TaskHound stands out by automating the discovery of dangerous scheduled tasks across Windows networks.

Instead of manually searching through system logs, the tool scans remote machines over SMB and parses task XML files to identify security weaknesses.

FeatureUse Case
Tier 0 DetectionIdentify high-value administrative account exposure
BloodHound IntegrationCorrelate tasks with attack paths for risk assessment
Password AnalysisWork with the existing BloodHound infrastructure
Offline AnalysisAnalyze tasks in OPSEC-conscious environments
BOF ImplementationBeacon-based operations without direct network access
Credential Guard DetectionEvaluate DPAPI dump success likelihood
SID ResolutionImprove readability in mixed SID/username environments
Multi-format SupportWork with existing BloodHound infrastructure
Flexible AuthenticationFlexible authentication for various network scenarios
Multiple Output FormatsIntegrate findings into security workflows and reporting

It looks for tasks running as administrative accounts, privileged users, or Tier 0 accounts, typically the highest-value targets for attackers.

The tool integrates with BloodHound, a popular network security visualization platform.

This integration enables security teams to automatically correlate scheduled tasks with BloodHound’s attack path data, revealing which tasks pose the most significant risk in their environment.

TaskHound includes several powerful features for threat hunters. It automatically detects tasks assigned to Tier 0 users, such as Domain Admins and Enterprise Admins.

The tool analyzes when credentials were last changed compared to when tasks were created, helping identify old passwords that could be vulnerable to offline cracking.

The platform supports both modern BloodHound Community Edition and legacy BloodHound formats, making it compatible with existing security infrastructure.

TaskHound can also work offline, analyzing previously collected XML files without requiring direct network access.

For operators using AdaptixC2, the tool includes a Beacon Object File implementation. During a penetration test, TaskHound quickly identifies exploitation opportunities.

Tasks running under compromised accounts can be manipulated to gain system access.

The tool provides detailed reporting showing task locations, associated credentials, creation dates, and recommended next steps for each finding.

Taskhound tool output

The creator emphasizes strict OPSEC (operational security) considerations. Since the tool relies on standard SMB operations, network defenders could detect its activity.

For sensitive assessments, users can employ the standalone BOF version or manually collect tasks for offline analysis.

The project roadmap includes a direct BloodHound database connector and a dedicated NetExec module to expand integration with other popular security frameworks.

The GitHub developer also plans automated credential extraction for offline decryption.

TaskHound fills an essential gap in Windows privilege-escalation assessment, automating a tedious manual process while providing actionable intelligence to security teams protecting enterprise networks.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

10 minutes ago

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…

12 minutes ago

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions…

19 minutes ago

Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach

Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to…

2 hours ago

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging…

3 hours ago

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

A critical remote code execution flaw in Microsoft's Windows Graphics Component allows attackers to seize…

14 hours ago