Interactive at.exe privilege escalation method
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Scheduled tasks Analytics
ATT&CK Tactic
Execution (TA0002), Privilege Escalation (TA0004)
ATT&CK Technique
Scheduled Task/Job (T1053), Scheduled Task/Job: At (T1053.002)
Severity
Low
Description
Detects an interactive AT scheduled task, which may be used as a form of privilege escalation.
Attacker's Goals
Attackers may attempt to use the command to gain persistence on the endpoint using recurring tasks.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Was this helpful?
