Hidden GhostTask Scheduled Task Persistence via Missing SD Value in TaskCache

Detects GhostTask-style hidden scheduled task persistence associated with the TWINLOOT Python implant framework. Legitimate scheduled tasks always write a security descriptor (SD) value under HKLM\...\Schedule\TaskCache\Tasks\<GUID>\SD alongside the corresponding HKLM\...\Schedule\TaskCache\Tree\<TaskName> entry. GhostTask abuses RegLoadAppKey/offreg.dll to build the TaskCache structure offline, producing a Tree entry and a Tasks\<GUID> key WITHOUT the accompanying SD value. The absence of the SD value combined with presence of the Tree entry is the key differentiator from normal task creation, which always writes SD. This technique is used by TWINLOOT to establish persistence while evading standard registry-event-based detections that rely on the presence of an SD value.