Compliance Node Overview
MITRE ATT&CK T1053.002 (At) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration, M1047 Audit, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1053/002/
SHA-256 integrity: f9437bcb92e1de9eab51130afd463d014c952c17ff5b0dc2d2bf123e464c2106
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1053.002: At (https://attack.mitre.org/techniques/T1053/002/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access