Uncommon AT task-job creation by user

Cortex XDR Analytics Alert Reference by Alert name

Product
Cortex XDR
Last date published
2024-10-08
Category
Analytics Alert Reference
Order
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Detector Tags

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Scheduled Task/Job: At (T1053.002)

Severity

Low

Description

An unpopular AT task-job was created by a user.

Attacker's Goals

Attackers may use at task-jobs for persistence or executing malicious files.

Investigative actions

Check the AT job task for suspicious activity.

Variations

Uncommon AT task-job creation by user from a web server process

Synopsis

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Scheduled Task/Job: At (T1053.002)

Severity

Medium

Description

A web process used the AT command to create a new AT task-job.

Attacker's Goals

Attackers may use at task-jobs for persistence or executing malicious files.

Investigative actions

Check the AT job task for suspicious activity.


Uncommon AT task-job creation by user from unpopular process

Synopsis

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Scheduled Task/Job: At (T1053.002)

Severity

Low

Description

An unpopular process created an AT task-job on the host, which is not popular in the organization.

Attacker's Goals

Attackers may use at task-jobs for persistence or executing malicious files.

Investigative actions

Check the AT job task for suspicious activity.