Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0005 — Scheduled Job Metadata
DC0005

Scheduled Job Metadata

9 analytic(s) · 3 detection strategy(ies)

Description

Contextual data about a scheduled job, which may include information such as name, timing, command(s), etc.

Referenced in Analytics

9
AN0325 Analytic 0325 DET0117

Creation or modification of `systemd` service units or cron jobs using deceptive naming and untrusted command paths, often followed by lateral network activity or privilege escalation.

auditd:CONFIG_CHANGE linux:osquery linux:cron
AN0326 Analytic 0326 DET0117

Creation of LaunchAgents or LaunchDaemons with names resembling known system services but executing non-Apple signed code or scripts.

fs:fileevents macos:endpointsecurity macos:unifiedlog
AN0430 Analytic 0430 DET0151

Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell etw:Microsoft-Windows-Kernel-Process WinEventLog:TaskScheduler WinEventLog:TaskScheduler EDR:Telemetry
AN0431 Analytic 0431 DET0151

A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.

auditd:SYSCALL auditd:SYSCALL linux:syslog linux:cron
AN0432 Analytic 0432 DET0151

Process/script execution of systemsetup -gettimezone, date, ioreg, or API usage (timeIntervalSinceNow, gettimeofday) followed by time-based scheduling (launchd plist modification) or sleep-based execution.

macos:unifiedlog macos:unifiedlog
AN0433 Analytic 0433 DET0151

Interactive or remote shell/API invocation of esxcli system clock get or querying time parameters via hostd/vpxa shortly followed by time/ntp configuration checks or scheduled task creation, executed by non-standard accounts or outside maintenance windows.

esxi:shell esxi:hostd esxi:syslog
AN1118 Analytic 1118 DET0399

Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System
AN1119 Analytic 1119 DET0399

Detection of cron-based or script-based recurring transfers where the same script, user, or destination reappears at predictable intervals.

auditd:SYSCALL linux:cron NSM:Flow
AN1120 Analytic 1120 DET0399

LaunchAgent or launchd recurring jobs initiating data transfer to consistent external IPs or domains with repeat timing signatures.

macos:endpointsecurity macos:launchd macos:unifiedlog

Details

MITRE ID
DC0005
STIX ID
x-mitre-data-component--7b375092-3a61-448d-900a-77c9a4bde4dc
Analytics
9
Detection Strategies
3
Leaving Threaticon

This link opens an external site that isn't part of the platform.