Windows process creation: interactive at.exe job execution
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
FreeUnreviewedSigmahighv1
windows-process-creation-interactive-at-exe-job-execution-60fc936d
title: "Windows process creation: interactive at.exe job execution"
id: 86abfdf4-a482-4bf1-aabb-46a2b34dc1a7
status: test
description: This rule flags Windows process executions where at.exe is launched with an interactive job indicator in the command line. Interactive AT jobs can be abused to run attacker-controlled commands under a different context, potentially aiding privilege escalation. It relies on process creation telemetry capturing the at.exe image path and the command-line argument containing the keyword 'interactive'.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1053.002/T1053.002.md
- https://eqllib.readthedocs.io/en/latest/analytics/d8db43cf-ed52-4f5c-9fb3-c9a4b95a0b56.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2021-11-27
tags:
- attack.persistence
- attack.execution
- attack.privilege-escalation
- attack.t1053.002
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \at.exe
CommandLine|contains: interactive
condition: selection
falsepositives:
- Unlikely (at.exe deprecated as of Windows 8)
level: high
simulation:
- type: atomic-red-team
name: At.exe Scheduled task
technique: T1053.002
atomic_guid: 4a6c0dc4-0f2a-4203-9298-a5a9bdc21ed8
license: DRL-1.1
related:
- id: 60fc936d-2eb0-4543-8a13-911c750a1dfc
type: derived
What it detects
This rule flags Windows process executions where at.exe is launched with an interactive job indicator in the command line. Interactive AT jobs can be abused to run attacker-controlled commands under a different context, potentially aiding privilege escalation. It relies on process creation telemetry capturing the at.exe image path and the command-line argument containing the keyword 'interactive'.
Known false positives
- Unlikely (at.exe deprecated as of Windows 8)
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.