1200KM / detection
T1053.002 At — Detection Rules
Detection workspace for T1053.002 At: 8 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote Schedule Task Lateral Movement via ATSvc · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:1ff70682-0a51-30e8-076d-740be8cee98b\""}
- Remote Schedule Task Lateral Movement via ITaskSchedulerService · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:86d35949-83c9-4044-b424-db363231fd0c\""}
- Remote Schedule Task Lateral Movement via SASec · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:378e52b0-c0a9-11cf-822d-00aa0051e40f\""}
- Scheduled Task/Job At · stable · low · {"product":"linux","category":"process_creation"}
- MITRE BZAR Indicators for Execution · test · medium · {"product":"zeek","service":"dce_rpc"}
- Remote Task Creation via ATSVC Named Pipe - Zeek · test · medium · {"product":"zeek","service":"smb_files"}
- Remote Task Creation via ATSVC Named Pipe · test · medium · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- Interactive AT Job · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0333 Cross-Platform Detection of Scheduled Task/Job Abuse via `at` Utility
AN0943 Analytic 0943
Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe.
AN0944 Analytic 0944
Detects usage of `at` command to schedule jobs, followed by job execution and modification of job files under /var/spool/cron/atjobs.
AN0945 Analytic 0945
Detects user or root invocation of `at` command to schedule a job, followed by job execution using LaunchServices and activity in /usr/lib/cron/at.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.