1200KM / simulation
T1053.003 Cron — Attack Simulation
Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths. An adversary may use cron in Linux or Unix environments to execute programs…
Technique description
Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths. An adversary may use cron in Linux or Unix environments to execute programs…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Cron - Add script to /etc/cron.d folder
Procedure 078e69eb-d9fb-450e-b9d0-2e118217c846; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Cron - Add script to /var/spool/cron/crontabs/ folder
Procedure 2d943c18-e74a-44bf-936f-25ade6cccab4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Cron - Replace crontab with referenced file
Procedure 435057fb-74b1-410e-9403-d81baf194f75; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Cron - Add script to all cron subfolders
Procedure b7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.