.. / At.exe
Star

Schedule periodic tasks


Paths:


Resources:
https://freddiebarrsmith.com/at.txt
https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html - Escalate to System from Administrator
https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems

Acknowledgement:
Freddie Barr-Smith -
Riccardo Spolaor -
Mariano Graziano -
Xabier Ugarte-Pedrero -


Detection:
Scheduled task is created
Windows event log - type 3 login
C:\Windows\System32\Tasks\At1 (substitute 1 with subsequent number of at job)
C:\Windows\Tasks\At1.job
Registry Key - Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\At1.



Execute

Create a recurring task to execute every day at a specific time.
C:\Windows\System32\at.exe at 09:00 /interactive /every:m,t,w,th,f,s,su C:\Windows\System32\revshell.exe
Usecase:Create a recurring task, to eg. to keep reverse shell session(s) alive
Privileges required:Local Admin
OS:Windows 7 or older
Mitre:T1053