Windows at.exe Interactive Job via Process Creation

Alerts on at.exe process launches that include 'interactive' in the command line on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-31
title: Windows at.exe Interactive Job via Process Creation
id: 86abfdf4-a482-4bf1-aabb-46a2b34dc1a7
status: test
description: This rule identifies execution of Windows at.exe when the command line contains the keyword "interactive". Interactive AT jobs can be used by an attacker to run commands in a way that supports follow-on access and potential privilege escalation. It relies on Windows process creation telemetry with the executable path and command-line content.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1053.002/T1053.002.md
  - https://eqllib.readthedocs.io/en/latest/analytics/d8db43cf-ed52-4f5c-9fb3-c9a4b95a0b56.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2021-11-27
tags:
  - attack.persistence
  - attack.execution
  - attack.privilege-escalation
  - attack.t1053.002
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: \at.exe
    CommandLine|contains: interactive
  condition: selection
falsepositives:
  - Unlikely (at.exe deprecated as of Windows 8)
level: high
simulation:
  - type: atomic-red-team
    name: At.exe Scheduled task
    technique: T1053.002
    atomic_guid: 4a6c0dc4-0f2a-4203-9298-a5a9bdc21ed8
license: DRL-1.1
related:
  - id: 60fc936d-2eb0-4543-8a13-911c750a1dfc
    type: derived