Sub-technique of T1053 Scheduled Task/Job.View on attack.mitre.org
Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. In addition to explicitly running the `at` command, adversaries may also schedule a task with at by directly leveraging the Windows Management Instrumentation `Win32_ScheduledJob` WMI class.
On Linux and macOS, at may be invoked by the superuser as well as any users added to the at.allow file. If the at.allow file does not exist, the at.deny file is checked. Every username not listed in at.deny is allowed to invoke at. If the at.deny exists and is empty, global use of at is permitted. If neither file exists (which is often the baseline) only the superuser is allowed to use at.
Adversaries may use at to execute programs at system startup or on a scheduled basis for Persistence. at can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM).
In Linux environments, adversaries may also abuse at to break out of restricted environments by using a task to spawn an interactive system shell or to run system commands. Similarly, at may also be used for Privilege Escalation if the binary is allowed to run as superuser via sudo.
Rules on DetectionCode tagged with T1053.002.
| Rule | Level | Log source |
|---|---|---|
| Interactive AT Job | high | windows / process_creation |
| Remote Schedule Task Lateral Movement via ATSvc | high | rpc_firewall / application |
| Remote Schedule Task Lateral Movement via ITaskSchedulerService | high | rpc_firewall / application |
| Remote Schedule Task Lateral Movement via SASec | high | rpc_firewall / application |
| MITRE BZAR Indicators for Execution | medium | zeek / NULL |
| Remote Task Creation via ATSVC Named Pipe | medium | windows / NULL |
| Remote Task Creation via ATSVC Named Pipe - Zeek | medium | zeek / NULL |
| Scheduled Task/Job At | low | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux At Application Execution | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Auditd At Application Execution | Anomaly | NULL | Linux Auditd Syscall |
| Linux Possible Append Command To At Allow Config File | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Scheduled Task Creation on Remote Endpoint using At | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT18 | APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement. |
| GroupThreat Group-3390 | Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network. |
| Used by | Procedure example |
|---|---|
| Toolat | at can be used to schedule a task on a system to be executed at a specific date or time. |
| ToolCrackMapExec | CrackMapExec can set a scheduled task on the target system to execute commands remotely using at. |
| MalwareMURKYTOP | MURKYTOP has the capability to schedule remote AT jobs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.