Windows process creation: interactive at.exe job execution

Alerts on at.exe process launches that include 'interactive' in the command line on Windows.

FreeUnreviewedSigmahighv1
title: "Windows process creation: interactive at.exe job execution"
id: 86abfdf4-a482-4bf1-aabb-46a2b34dc1a7
status: test
description: This rule flags Windows process executions where at.exe is launched with an interactive job indicator in the command line. Interactive AT jobs can be abused to run attacker-controlled commands under a different context, potentially aiding privilege escalation. It relies on process creation telemetry capturing the at.exe image path and the command-line argument containing the keyword 'interactive'.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1053.002/T1053.002.md
  - https://eqllib.readthedocs.io/en/latest/analytics/d8db43cf-ed52-4f5c-9fb3-c9a4b95a0b56.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2021-11-27
tags:
  - attack.persistence
  - attack.execution
  - attack.privilege-escalation
  - attack.t1053.002
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: \at.exe
    CommandLine|contains: interactive
  condition: selection
falsepositives:
  - Unlikely (at.exe deprecated as of Windows 8)
level: high
simulation:
  - type: atomic-red-team
    name: At.exe Scheduled task
    technique: T1053.002
    atomic_guid: 4a6c0dc4-0f2a-4203-9298-a5a9bdc21ed8
license: DRL-1.1
related:
  - id: 60fc936d-2eb0-4543-8a13-911c750a1dfc
    type: derived

What it detects

This rule flags Windows process executions where at.exe is launched with an interactive job indicator in the command line. Interactive AT jobs can be abused to run attacker-controlled commands under a different context, potentially aiding privilege escalation. It relies on process creation telemetry capturing the at.exe image path and the command-line argument containing the keyword 'interactive'.

Known false positives

  • Unlikely (at.exe deprecated as of Windows 8)

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.