Windows at.exe Interactive Job via Process Creation

Alerts on at.exe process launches that include 'interactive' in the command line on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies execution of Windows at.exe when the command line contains the keyword "interactive". Interactive AT jobs can be used by an attacker to run commands in a way that supports follow-on access and potential privilege escalation. It relies on Windows process creation telemetry with the executable path and command-line content.

Related detections5 linkedT1053.002 — drag to rearrange
Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)
Remote ITaskSchedulerService RPC Create/Execute Scheduled Tasks Used for Lateral Movement
RPC Firewall Alerts for Remote Scheduled Task Creation/Execution via SASec
Linux at/atd Process Execution via /at or /atd
Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Windows at.exe Interactive Job via Process Creation
Pivot detection · T1053.002 · 5 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.