DFSP # 470 The Windows Taskhosts
Digital Forensic Survival Podcast - A podcast by Digital Forensic Survival Podcast - Tuesdays

Categories:
This week I'm talking about the three task hosts. These are Windows core files, and they share not only similar names, but similar functionality. Because of this, there is the potential for confusion, which may allow an attacker to leverage these similarities and mask they are malware. My goal in this episode is to demystify the three different task hosts, and provide the necessary insight for proper triage if any of these files come up during your investigations.