[rule]
description = """
Detects the execution of an unsigned or untrusted binary by Cron. Cron is a common persistence mechanism used by threat
actors, even on macOS. A recent DPRK sample dubbed "ThiefBucket" utilized Cron for persistence in order to executed an
unsigned payload. The use of Cron is not entirely common on macOS and using it to execute an unsigned or untrusted
application is even more unusual.
"""
id = "d18ce577-74ba-40c3-9f9f-6031dfe76b2c"
license = "Elastic License v2"
name = "Unsigned or Untrusted binary Execution via Cron"
os_list = ["macos"]
reference = ["https://www.jamf.com/blog/jamf-threat-labs-observes-targeted-attacks-amid-fbi-warnings/"]
version = "1.0.6"
query = '''
process where event.type == "start" and event.action == "exec" and process.parent.name == "cron" and
(process.code_signature.trusted == false or process.code_signature.exists == false) and
(process.Ext.effective_parent.executable == "/usr/sbin/cron" or process.Ext.effective_parent.name like~ ".*")
'''
min_endpoint_version = "8.11.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1053"
name = "Scheduled Task/Job"
reference = "https://attack.mitre.org/techniques/T1053/"
[[threat.technique.subtechnique]]
id = "T1053.003"
name = "Cron"
reference = "https://attack.mitre.org/techniques/T1053/003/"
[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1053"
name = "Scheduled Task/Job"
reference = "https://attack.mitre.org/techniques/T1053/"
[[threat.technique.subtechnique]]
id = "T1053.003"
name = "Cron"
reference = "https://attack.mitre.org/techniques/T1053/003/"
[threat.tactic]
id = "TA0003"
name = "Persistence"
reference = "https://attack.mitre.org/tactics/TA0003/"
[internal]
min_endpoint_version = "8.11.0"