Cross-source coverage
T1053.003 / ATT&CK
Scheduled Task/Job: Cron
48 rules across 9 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths.
An adversary may use cron in Linux or Unix environments to execute programs at system startup or on a scheduled basis for Persistence. In ESXi environments, cron jobs must be created directly via the crontab file (e.g., /var/spool/cron/crontabs/root).
- Tactics
- Execution · Persistence · Privilege Escalation
- Platforms
- Linux · macOS · ESXi
- Telemetry
-
auditd:SYSCALLmacos:unifiedlogfs:fsusageesxi:hostdesxi:cronesxi:vmkernel
How MITRE says to detect it DET0290
Cross-Platform Detection of Cron Job Abuse for Persistence and Execution
Linux Analytic 0805
Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals.
auditd:SYSCALLwriteauditd:SYSCALLexecve
macOS Analytic 0806
Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts.
macos:unifiedlogprocess: crontab edits, launch of cron jobfs:fsusagefile access to /usr/lib/cron/tabs/ and cron output files
ESXi Analytic 0807
Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence.
esxi:hostdmodification of crontab or local.sh entriesesxi:cronexecution of scheduled jobesxi:vmkernelspawned shell or execution environment activity
elastic/detection-rules
14 rules| Detection | Severity | Format |
|---|---|---|
| Potential Redis CONFIG SET Cron Directory Persistence (RedisRaider) | High | Elastic TOML |
| Privilege Escalation via Root Crontab File Modification | High | Elastic TOML |
| Suspicious Echo or Printf Execution Detected via Defend for Containers | High | Elastic TOML |
| Suspicious Execution from Foomatic-rip or Cupsd Parent | High | Elastic TOML |
| Cron Job Created or Modified | Medium | Elastic TOML |
| Deprecated - Suspicious File Creation in /etc for Persistence | Medium | Elastic TOML |
| Executable Bit Set for Potential Persistence Script | Medium | Elastic TOML |
| Pod or Container Creation with Suspicious Command-Line | Medium | Elastic TOML |
| Suspicious CronTab Creation or Modification | Medium | Elastic TOML |
| Modification of Persistence Relevant Files Detected via Defend for Containers | Low | Elastic TOML |
+ 4 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
10 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Isovalent - Cron Job Creation | Undefined | SPL |
| Cisco Secure Firewall - Wget or Curl Download | Undefined | SPL |
| Linux Add Files In Known Crontab Directories | Undefined | SPL |
| Linux Adding Crontab Using List Parameter | Undefined | SPL |
| Linux At Allow Config File Creation | Undefined | SPL |
| Linux Auditd Edit Cron Table Parameter | Undefined | SPL |
| Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File | Undefined | SPL |
| Linux Edit Cron Table Parameter | Undefined | SPL |
| Linux Possible Append Cronjob Entry on Existing Cronjob File | Undefined | SPL |
| Linux Possible Cronjob Modification With Editor | Undefined | SPL |
elastic/protections-artifacts
8 rules| Detection | Severity | Format |
|---|---|---|
| Cron Tab Creation or Modification via Shell Command | Undefined | Elastic TOML |
| Hidden Payload Executed via Scheduled Job | Undefined | Elastic TOML |
| Potential Persistence via Direct Crontab Modification | Undefined | Elastic TOML |
| Potential Privilege Escalation via Root Crontab File Modification | Undefined | Elastic TOML |
| Scheduled Job Executing Binary in Unusual Location | Undefined | Elastic TOML |
| Suspicious Echo Execution | Undefined | Elastic TOML |
| Unsigned or Untrusted binary Execution via Cron | Undefined | Elastic TOML |
| Unusual Command Execution via Cron | Undefined | Elastic TOML |
SigmaHQ/sigma
6 rules| Detection | Severity | Format |
|---|---|---|
| Triple Cross eBPF Rootkit Default Persistence | High | Sigma |
| Azure Kubernetes CronJob | Medium | Sigma |
| Modifying Crontab | Medium | Sigma |
| Scheduled Cron Task/Job - Linux | Medium | Sigma |
| Scheduled Cron Task/Job - MacOs | Medium | Sigma |
| New Cron File Created | Low | Sigma |
socfortress/Wazuh-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| File created or modified in /etc/cron.d using shell or echo/tee | High | Wazuh XML |
| Possible persistence: writing cron job to /var/spool/cron/crontabs | High | Wazuh XML |
| Script created in /etc/cron.(daily|hourly|weekly|monthly) for persistence | High | Wazuh XML |
| Modification of crontab detected (Potential persistence mechanism) | Medium | Wazuh XML |
| Suspicious shell execution from cron folder (Possible malicious scheduled task) | Medium | Wazuh XML |
panther-labs/panther-analysis
2 rules| Detection | Severity | Format |
|---|---|---|
| GCP GKE Kubernetes Cron Job Created Or Modified | Medium | Panther Python |
| Kubernetes CronJob Created or Modified | Informational | Panther Python |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| Root's crontab entry changed. | Medium | Wazuh XML |
chainguard-dev/osquery-defense-kit
1 rule| Detection | Severity | Format |
|---|---|---|
| Unexpected crontab entries | Undefined | osquery SQL |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Schedule Cron Jobs | Low | Falco YAML |