Cross-source coverage

T1053.003 / ATT&CK

Scheduled Task/Job: Cron

48 rules across 9 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths.

An adversary may use cron in Linux or Unix environments to execute programs at system startup or on a scheduled basis for Persistence. In ESXi environments, cron jobs must be created directly via the crontab file (e.g., /var/spool/cron/crontabs/root).

Platforms
Linux · macOS · ESXi
Telemetry
auditd:SYSCALLmacos:unifiedlogfs:fsusageesxi:hostdesxi:cronesxi:vmkernel

How MITRE says to detect it DET0290

Cross-Platform Detection of Cron Job Abuse for Persistence and Execution

Linux Analytic 0805

Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals.

  • auditd:SYSCALL write
  • auditd:SYSCALL execve

macOS Analytic 0806

Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts.

  • macos:unifiedlog process: crontab edits, launch of cron job
  • fs:fsusage file access to /usr/lib/cron/tabs/ and cron output files

ESXi Analytic 0807

Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence.

  • esxi:hostd modification of crontab or local.sh entries
  • esxi:cron execution of scheduled job
  • esxi:vmkernel spawned shell or execution environment activity

elastic/detection-rules

14 rules
Detection Severity Format
Potential Redis CONFIG SET Cron Directory Persistence (RedisRaider) High Elastic TOML
Privilege Escalation via Root Crontab File Modification High Elastic TOML
Suspicious Echo or Printf Execution Detected via Defend for Containers High Elastic TOML
Suspicious Execution from Foomatic-rip or Cupsd Parent High Elastic TOML
Cron Job Created or Modified Medium Elastic TOML
Deprecated - Suspicious File Creation in /etc for Persistence Medium Elastic TOML
Executable Bit Set for Potential Persistence Script Medium Elastic TOML
Pod or Container Creation with Suspicious Command-Line Medium Elastic TOML
Suspicious CronTab Creation or Modification Medium Elastic TOML
Modification of Persistence Relevant Files Detected via Defend for Containers Low Elastic TOML

+ 4 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

10 rules
Detection Severity Format
Cisco Isovalent - Cron Job Creation Undefined SPL
Cisco Secure Firewall - Wget or Curl Download Undefined SPL
Linux Add Files In Known Crontab Directories Undefined SPL
Linux Adding Crontab Using List Parameter Undefined SPL
Linux At Allow Config File Creation Undefined SPL
Linux Auditd Edit Cron Table Parameter Undefined SPL
Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File Undefined SPL
Linux Edit Cron Table Parameter Undefined SPL
Linux Possible Append Cronjob Entry on Existing Cronjob File Undefined SPL
Linux Possible Cronjob Modification With Editor Undefined SPL

elastic/protections-artifacts

8 rules
Detection Severity Format
Cron Tab Creation or Modification via Shell Command Undefined Elastic TOML
Hidden Payload Executed via Scheduled Job Undefined Elastic TOML
Potential Persistence via Direct Crontab Modification Undefined Elastic TOML
Potential Privilege Escalation via Root Crontab File Modification Undefined Elastic TOML
Scheduled Job Executing Binary in Unusual Location Undefined Elastic TOML
Suspicious Echo Execution Undefined Elastic TOML
Unsigned or Untrusted binary Execution via Cron Undefined Elastic TOML
Unusual Command Execution via Cron Undefined Elastic TOML

SigmaHQ/sigma

6 rules
Detection Severity Format
Triple Cross eBPF Rootkit Default Persistence High Sigma
Azure Kubernetes CronJob Medium Sigma
Modifying Crontab Medium Sigma
Scheduled Cron Task/Job - Linux Medium Sigma
Scheduled Cron Task/Job - MacOs Medium Sigma
New Cron File Created Low Sigma

socfortress/Wazuh-Rules

5 rules
Detection Severity Format
File created or modified in /etc/cron.d using shell or echo/tee High Wazuh XML
Possible persistence: writing cron job to /var/spool/cron/crontabs High Wazuh XML
Script created in /etc/cron.(daily|hourly|weekly|monthly) for persistence High Wazuh XML
Modification of crontab detected (Potential persistence mechanism) Medium Wazuh XML
Suspicious shell execution from cron folder (Possible malicious scheduled task) Medium Wazuh XML

panther-labs/panther-analysis

2 rules
Detection Severity Format
GCP GKE Kubernetes Cron Job Created Or Modified Medium Panther Python
Kubernetes CronJob Created or Modified Informational Panther Python

Wazuh Core Ruleset

1 rule
Detection Severity Format
Root's crontab entry changed. Medium Wazuh XML

chainguard-dev/osquery-defense-kit

1 rule
Detection Severity Format
Unexpected crontab entries Undefined osquery SQL

falcosecurity/rules

1 rule
Detection Severity Format
Schedule Cron Jobs Low Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.