Skip to content

Do not hide all scheduled tasks under Microsoft paths #132

Description

@ndemou

Problem

HealthTest-ListScheduledTasks suppresses every task whose path starts with \Microsoft\Windows\ or \Microsoft\Office\, based only on the task path.

File: health-tests/HealthTest-ListScheduledTasks.ps1, lines 36-58.

That hides new or changed task definitions in those folders, including a third-party or malicious task placed under a trusted-looking path.

Simple example

A new task is created as:

\Microsoft\Windows\Maintenance\UnexpectedUpdater

It runs an unknown executable as SYSTEM. The policy inventory skips it before checking its action, publisher, principal, or fingerprint, so it never appears for review.

Expected behavior

Do not trust a task solely because of its folder. Reduce noise using a maintained identity/publisher baseline or emit suppressed policy findings that remain available for change detection.

Acceptance criteria

  • A new non-Microsoft task under a Microsoft-looking path is discoverable.
  • Known built-in tasks remain low-noise.
  • Suppression considers definition identity, not only path text.
  • Unit tests cover a known built-in task and the example above.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions