reg_hunter
reg_hunter copied to clipboard
Add ScheduledTask examination and collection
This may require using COM, at least it did with PowerShell.
Field names: timestamp device_domain device_name default_hash task_path name status enabled account_domain account_name next_run last_run last_result description run_as_domain run_as_account logon_mode hidden priority path command_line (path to binary to execute + arguments) start_in logon_trigger