Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
FreeReviewedSigma · High · v2
- Product
- windows
- Category
- process_creation
- Author
- E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-10-24
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies execution of Windows at.exe when the command line contains the keyword "interactive". Interactive AT jobs can be used by an attacker to run commands in a way that supports follow-on access and potential privilege escalation. It relies on Windows process creation telemetry with the executable path and command-line content.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1053.002/T1053.002.md
- eqllib.readthedocs.iohttps://eqllib.readthedocs.io/en/latest/analytics/d8db43cf-ed52-4f5c-9fb3-c9a4b95a0b56.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-process-creation-interactive-at-exe-job-execution-60fc936d
title: Windows at.exe Interactive Job via Process Creation
id: 86abfdf4-a482-4bf1-aabb-46a2b34dc1a7
status: test
description: This rule identifies execution of Windows at.exe when the command line contains the keyword "interactive". Interactive AT jobs can be used by an attacker to run commands in a way that supports follow-on access and potential privilege escalation. It relies on Windows process creation telemetry with the executable path and command-line content.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1053.002/T1053.002.md
- https://eqllib.readthedocs.io/en/latest/analytics/d8db43cf-ed52-4f5c-9fb3-c9a4b95a0b56.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2021-11-27
tags:
- attack.persistence
- attack.execution
- attack.privilege-escalation
- attack.t1053.002
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \at.exe
CommandLine|contains: interactive
condition: selection
falsepositives:
- Unlikely (at.exe deprecated as of Windows 8)
level: high
simulation:
- type: atomic-red-team
name: At.exe Scheduled task
technique: T1053.002
atomic_guid: 4a6c0dc4-0f2a-4203-9298-a5a9bdc21ed8
license: DRL-1.1
related:
- id: 60fc936d-2eb0-4543-8a13-911c750a1dfc
type: derived