Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0012 — Scheduled Job Modification
DC0012

Scheduled Job Modification

3 analytic(s) · 3 detection strategy(ies)

Description

Changes made to an existing scheduled job, including modifications to its execution parameters, command payload, or execution timing.

Referenced in Analytics

3
AN0325 Analytic 0325 DET0117

Creation or modification of `systemd` service units or cron jobs using deceptive naming and untrusted command paths, often followed by lateral network activity or privilege escalation.

auditd:CONFIG_CHANGE linux:osquery linux:cron
AN0525 Analytic 0525 DET0184

Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion.

m365:exchange m365:unified
AN1221 Analytic 1221 DET0441

Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon

Details

MITRE ID
DC0012
STIX ID
x-mitre-data-component--faa34cf6-cf32-4dc9-bd6a-8f7a606ff65b
Analytics
3
Detection Strategies
3
Leaving Threaticon

This link opens an external site that isn't part of the platform.