kevmap

TechniquesT1053 › T1053.002

T1053.002 At

execution · persistence · privilege escalation — Windows, Linux, macOS · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
8
Sigma rules tagged attack.t1053.002
0
KEV CVEs mapped here
<p>Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. In addition to explicitly running the at command, adversaries may also schedule a task with at by directly leveraging the Windows Management Instrumentation Win32_ScheduledJob WMI class.</p><p>On Linux and macOS, at may be invoked by the superuser as well as any users added to the <code>at.allow</code> file. If the <code>at.allow</code> file does not exist, the <code>at.deny</code> file is checked. Every username not listed in <code>at.deny</code> is allowed to invoke at. If the <code>at.deny</code> exists and is empty, global use of at is permitted. If neither file exists (which is often the baseline) only the superuser is allowed to use at.</p><p>Adversaries may use at to execute programs at system startup or on a scheduled basis for Persistence. at can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM).</p><p>In Linux environments, adversaries may also abuse at to break out of restricted environments by using a task to spawn an interactive system shell or to run system commands. Similarly, at may also be used for Privilege Escalation if the binary is allowed to run as superuser via <code>sudo</code>.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1053.002

Author: Sagie Dulce, Dekel Paz · 2022-01-01 · logsource: product=rpc_firewall category=application · 0fcd1c79-4eeb-4746-aba9-1b458f7a79cb
Detects remote RPC calls to create or execute a scheduled task via ATSvc
Techniques: T1053T1053.002
Author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community · 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 60fc936d-2eb0-4543-8a13-911c750a1dfc
Detects an interactive AT job, which may be used as a form of privilege escalation.
Techniques: T1053.002
Author: Sagie Dulce, Dekel Paz · 2022-01-01 · logsource: product=rpc_firewall category=application · ace3ff54-e7fd-46bd-8ea0-74b49a0aca1d
Detects remote RPC calls to create or execute a scheduled task
Techniques: T1053T1053.002
Author: Sagie Dulce, Dekel Paz · 2022-01-01 · logsource: product=rpc_firewall category=application · aff229ab-f8cd-447b-b215-084d11e79eb0
Detects remote RPC calls to create or execute a scheduled task via SASec
Techniques: T1053T1053.002
Author: @neu5ron, SOC Prime · 2020-03-19 (modified 2021-11-27) · logsource: product=zeek service=dce_rpc · b640c0b8-87f8-4daa-aef8-95a24261dd1d
Windows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE
Author: Ömer Günal, oscd.community · 2020-10-06 (modified 2022-07-07) · logsource: product=linux category=process_creation · d2d642d7-b393-43fe-bae4-e81ed5915c4b
Detects the use of at/atd which are utilities that are used to schedule tasks. They are often abused by adversaries to maintain persistence or to perform task scheduling for initial or recurring execution of malicious code
Techniques: T1053.002
Author: Samir Bousseaden, @neu5rn · 2020-04-03 (modified 2022-12-27) · logsource: product=zeek service=smb_files · dde85b37-40cd-4a94-b00c-0b8794f956b5
Detects remote task creation via at.exe or API interacting with ATSVC namedpipe
Techniques: T1053.002
Author: Samir Bousseaden · 2019-04-03 (modified 2024-08-01) · logsource: product=windows service=security · f6de6525-4509-495a-8a82-1f8b0ed73a00
Detects remote task creation via at.exe or API interacting with ATSVC namedpipe
Techniques: T1053.002

Rules tagged at the parent level (attack.t1053) 12

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Thomas Patzke · 2020-05-22 (modified 2023-11-06) · logsource: product=windows category=process_creation · 058f4380-962d-40a5-afce-50207d36d7e2
Detects various execution patterns of the CrackMapExec pentesting framework
Author: Sagie Dulce, Dekel Paz · 2022-01-01 · logsource: product=rpc_firewall category=application · 0fcd1c79-4eeb-4746-aba9-1b458f7a79cb
Detects remote RPC calls to create or execute a scheduled task via ATSvc
Techniques: T1053T1053.002
Author: Florian Roth (Nextron Systems) · 2022-09-15 (modified 2023-02-04) · logsource: product=windows category=process_creation · 26488ad0-f9fd-4536-876f-52fea846a2e4
Detects the execution of the hacktool SharPersist - used to deploy various different kinds of persistence mechanisms
Techniques: T1053
Author: Florian Roth (Nextron Systems) · 2022-02-25 (modified 2023-03-08) · logsource: product=windows category=process_creation · 42a993dd-bb3e-48c8-b372-4d6684c4106c
This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
Author: Syed Hasan (@syedhasan009) · 2021-06-18 (modified 2025-10-22) · logsource: product=windows category=registry_set · 4720b7df-40c3-48fd-bbdf-fd4b3c464f0d
Monitor the creation of a new key under 'TaskCache' when a new scheduled task is registered by a process that is not svchost.exe, which is suspicious
Techniques: T1053T1053.005
Author: Austin Clark · 2019-08-12 (modified 2025-04-28) · logsource: product=cisco service=aaa · 671ffc77-50a7-464f-9e3d-9ea2b493b26b
Modifications to a config that will serve an adversary's impacts or persistence
Author: Florian Roth (Nextron Systems) · 2021-11-16 (modified 2022-01-12) · logsource: product=windows category=file_event · 80e1f67a-4596-4351-98f5-a9c3efabac95
Detects the creation of tasks from processes executed from suspicious locations
Techniques: T1053
Author: Sagie Dulce, Dekel Paz · 2022-01-01 · logsource: product=rpc_firewall category=application · ace3ff54-e7fd-46bd-8ea0-74b49a0aca1d
Detects remote RPC calls to create or execute a scheduled task
Techniques: T1053T1053.002
Author: Sagie Dulce, Dekel Paz · 2022-01-01 · logsource: product=rpc_firewall category=application · aff229ab-f8cd-447b-b215-084d11e79eb0
Detects remote RPC calls to create or execute a scheduled task via SASec
Techniques: T1053T1053.002
Author: Florian Roth (Nextron Systems) · 2021-03-09 (modified 2023-03-09) · logsource: product=windows category=process_creation · bbb2dedd-a0e3-46ab-ba6c-6c82ae7a9aa7
Detects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers
Techniques: T1546T1053
Author: Florian Roth (Nextron Systems), Bartlomiej Czyz (@bczyz1) · 2019-03-04 (modified 2022-11-27) · logsource: product=windows service=security · c5a178bf-9cfb-4340-b584-e4df39b6a3e7
Detects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group
Techniques: T1053
Author: Andreas Hunkeler (@Karneades) · 2022-02-07 (modified 2023-03-18) · logsource: product=windows category=process_creation · e1118a8f-82f5-44b3-bb6b-8a284e5df602
Detects specific process parameters as used by ACTINIUM scheduled task persistence creation.
Techniques: T1053T1053.005