{
  "node_id": "mitre-attack-t1053-002-at",
  "title": "MITRE ATT&CK T1053.002: At (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1053.002 (At) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration, M1047 Audit, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, CM-06, CM-07.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1053-scheduled-task-job"
  ],
  "primary_citations_count": 7
}