1200KM / detection
T1053.003 Cron — Detection Rules
Detection workspace for T1053.003 Cron: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Azure Kubernetes CronJob · test · medium · {"product":"azure","service":"activitylogs"}
- Modifying Crontab · test · medium · {"product":"linux","service":"cron"}
- New Cron File Created · experimental · low · {"product":"linux","category":"file_event"}
- Triple Cross eBPF Rootkit Default Persistence · test · high · {"product":"linux","category":"file_event"}
- Scheduled Cron Task/Job - Linux · test · medium · {"category":"process_creation","product":"linux"}
- Scheduled Cron Task/Job - MacOs · test · medium · {"category":"process_creation","product":"macos"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0290 Cross-Platform Detection of Cron Job Abuse for Persistence and Execution
AN0805 Analytic 0805
Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals.
AN0806 Analytic 0806
Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts.
AN0807 Analytic 0807
Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1053.003 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.