Suspicious Legacy at.exe Scheduled Job Creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-26
Updated
2026-09-26

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects use of the deprecated at.exe utility to schedule jobs. Modern Windows administration relies on schtasks, so at.exe execution is uncommon and often tied to adversary persistence or lateral movement. Its rarity in legitimate use makes it a useful hunting signal.

Related detections6 linkedT1053.002 — drag to rearrange
Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)
Remote ITaskSchedulerService RPC Create/Execute Scheduled Tasks Used for Lateral Movement
RPC Firewall Alerts for Remote Scheduled Task Creation/Execution via SASec
Linux at/atd Process Execution via /at or /atd
Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Windows at.exe Interactive Job via Process Creation
Suspicious Legacy at.exe Scheduled Job Creation
Pivot detection · T1053.002 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.