Analytics BIOC Low

Interactive at.exe privilege escalation method

Detects an interactive AT scheduled task, which may be used as a form of privilege escalation.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Privilege Escalation (TA0004)
ATT&CK techniques: Scheduled Task/Job (T1053) Scheduled Task/Job: At (T1053.002)
Detector tags: Scheduled tasks Analytics
Attacker's goals:

Attackers may attempt to use the command to gain persistence on the endpoint using recurring tasks.

Investigative actions:

Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

Test period:
N/A (single event)
Deduplication:
1 Day