Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.002 At |
GroupAPT18 | APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network. |
| T1059.003 Windows Command Shell |
MalwarehcdLoader | hcdLoader provides command-line access to the compromised system. |
| T1070.004 File Deletion |
GroupAPT18 | APT18 actors deleted tools and batch files from victim systems. |
| T1543.003 Windows Service |
MalwarehcdLoader | hcdLoader installs itself as a service for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.