Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TaskHound — Tool to enumerate privileged Scheduled Tasks on Remote Systems | Kitploit
Tools/GitHubGitHub/1r0bit/taskhound
Privilege EscalationReconnaissanceLateral MovementInformation GatheringPost-ExploitationPenetration TestingRed Teaming
GitHub1r0bit/taskhound

TaskHound

Tool to enumerate privileged Scheduled Tasks on Remote Systems

View Repository
31225251 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

TaskHound Logo

Windows Privileged Scheduled Task Discovery Tool for fun and profit.

Latest Release BloodHound OpenGraph Python 3.11+
Ask DeepWiki Twitter Blog


TaskHound hunts for Windows scheduled tasks that run with privileged accounts and stored credentials. It enumerates tasks over SMB, parses XMLs, and identifies high-value attack opportunities through BloodHound integration.

For backstory/lore and detailed explanations: see the associated Blog Posts - Part 1 and Part 2.

Key Features

FeatureDescription
Tier 0 & High Value DetectionAutomatically identifies tasks running as Domain Admins, Enterprise Admins, and other privileged accounts
BloodHound IntegrationConnect to live BHCE/Legacy instances or ingest exports for high-value user detection
OpenGraph SupportVisualize scheduled tasks as attack path nodes in BloodHound CE
LAPS IntegrationAuto-retrieve and use LAPS passwords (both Windows LAPS and Legacy) for per-host authentication
DPAPI Credential ExtractionCollect and decrypt DPAPI blobs containing stored task credentials
Multi-threaded ScanningParallel target processing with rate limiting for large environments
LDAP-based Tier-0 DetectionDetect privileged accounts via group membership without BloodHound
Credential ValidationVerify if stored task passwords are still valid via RPC
Offline AnalysisProcess mounted disk images or previously collected XMLs
Multiple Output FormatsPlain text, JSON, CSV, and HTML security reports with severity scoring
SID ResolutionMulti-tier resolution via BloodHound → Cache → LSARPC → LDAP → GC
CachingSQLite-based persistent cache for SID lookups and LAPS credentials

Quick Start

# Install
git clone https://github.com/1r0BIT/TaskHound.git
cd TaskHound
python3 -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt && pip install .

# Basic usage - single target
taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local -t moe.thesimpsons.local

# Multiple targets with threading
taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --targets-file hosts.txt --threads 10

# Auto-discover all domain computers
taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --dc-ip 10.0.0.1 --auto-targets --threads 20

# With LAPS - auto-retrieves per-host local admin passwords
taskhound -u homer.simpson -p 'Doh!123' -d thesimpsons.local --targets-file hosts.txt --laps --threads 10

# Offline analysis of mounted disk image
taskhound --offline-disk /mnt/disk

Auth Support: TaskHound supports most major authentication mechanisms including password, NTLM hash, Kerberos (also with ccache), and AES key authentication.

Configuration File

TaskHound supports TOML configuration files for persistent settings. Create taskhound.toml in your working directory or ~/.config/taskhound/:

[authentication]
username = "svc_taskhound"
domain = "THESIMPSONS.LOCAL"

[target]
dc_ip = "10.0.0.1"
threads = 10
timeout = 30

[bloodhound]
live = true
connector = "http://127.0.0.1:8080"
api_key = "${BH_API_KEY}"      # Use env vars for secrets
api_key_id = "${BH_API_KEY_ID}"
type = "bhce"

[bloodhound.opengraph]
enabled = true
output_dir = "./opengraph"

[laps]
enabled = true

[cache]
enabled = true
ttl = 86400  # 24 hours

Priority: CLI args > Environment variables > Local config > User config > Defaults

AdaptixC2 Integration

TaskHound's BOF is included in the Adaptix Extension-Kit under SAR-BOF/taskhound/.

Demo Output

TTTTT  AAA   SSS  K   K H   H  OOO  U   U N   N DDDD
  T   A   A S     K  K  H   H O   O U   U NN  N D   D
  T   AAAAA  SSS  KKK   HHHHH O   O U   U N N N D   D
  T   A   A     S K  K  H   H O   O U   U N  NN D   D
  T   A   A SSSS  K   K H   H  OOO   UUU  N   N DDDD

                     by 0xr0BIT

[+] Connecting to BloodHound CE at http://127.0.0.1:8080
[+] BloodHound connection successful (API v2)
[+] High Value target data loaded (42 users)
[+] OpenGraph generation enabled (auto-upload active)
[*] Processing target: moe.thesimpsons.local
[+] moe.thesimpsons.local: Connected via SMB
[+] moe.thesimpsons.local: Local Admin Access confirmed
[*] moe.thesimpsons.local: Enumerating scheduled tasks (skipping \Microsoft)
[+] moe.thesimpsons.local: Found 12 tasks (3 privileged, 2 with stored credentials)

┌──────────────────────────────────────────────────────────────────────────────┐
│ [TIER-0] moe.thesimpsons.local - \DuffBrewery\BackupJob                      │
├──────────────────────────────────────────────────────────────────────────────┤
│ Enabled          │ True                                                      │
│ RunAs            │ THESIMPSONS\Administrator                                 │
│ What             │ C:\Scripts\backup_beer_recipes.ps1                        │
│ Author           │ THESIMPSONS\burns.monty                                   │
│ Date             │ 2025-06-15T02:30:00                                       │
│ Trigger          │ Calendar (starts 2025-06-15 02:30, daily)                 │
│ Reason           │ Tier 0 - Domain Admins membership                         │
│ Cred Validation  │ CONFIRMED_VALID                                           │
│ Pwd Analysis     │ Password unchanged AND ran within schedule - confirmed    │
└──────────────────────────────────────────────────────────────────────────────┘

┌──────────────────────────────────────────────────────────────────────────────┐
│ [PRIV] moe.thesimpsons.local - \KrustyBurger\InventorySync                   │
├──────────────────────────────────────────────────────────────────────────────┤
│ Enabled          │ True                                                      │
│ RunAs            │ THESIMPSONS\svc_krusty                                    │
│ What             │ C:\KrustyApps\sync.exe --silent                           │
│ Author           │ THESIMPSONS\carlson.carl                                  │
│ Date             │ 2025-03-10T08:00:00                                       │
│ Trigger          │ Calendar (starts 2025-03-10 08:00, every 4 hours)         │
│ Reason           │ High Value match found in BloodHound                      │
│ Cred Validation  │ DEFINITELY_STALE                                          │
│ Pwd Analysis     │ Password changed AFTER last run - credentials are stale   │
└──────────────────────────────────────────────────────────────────────────────┘
Download Tool