Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0001 — Scheduled Job Creation
DC0001

Scheduled Job Creation

21 analytic(s) · 15 detection strategy(ies)

Description

The establishment of a task or job that will execute at a predefined time or based on specific triggers.

Referenced in Analytics

21
AN0024 Analytic 0024 DET0010

Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes.

WinEventLog:Security WinEventLog:WMI WinEventLog:Security WinEventLog:Sysmon
AN0025 Analytic 0025 DET0010

Detects inotify or auditd configuration changes that monitor system files coupled with execution of script interpreters or binaries by cron or systemd timers.

auditd:SYSCALL linux:syslog auditd:SYSCALL
AN0113 Analytic 0113 DET0040

Detects adversary activity that removes persistence artifacts such as services, registry keys, scheduled tasks, user accounts, and binaries through commands like `sc delete`, `schtasks /delete`, or `reg delete`.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:TaskScheduler WinEventLog:Security
AN0258 Analytic 0258 DET0094

Detects creation or modification of scheduled tasks using schtasks.exe, at.exe, or COM objects followed by execution of outlier processes tied to the scheduled job.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0259 Analytic 0259 DET0094

Detects creation or modification of cron jobs via crontab, /etc/cron.* directories, or systemd timer units with execution by unusual users or non-standard intervals.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0260 Analytic 0260 DET0094

Detects creation or alteration of LaunchAgents or LaunchDaemons with corresponding plist modification followed by execution of associated binaries.

macos:unifiedlog fs:fsusage macos:osquery
AN0262 Analytic 0262 DET0094

Detects modification of ESXi cron jobs, local.sh scripts, or scheduled API calls to persist custom binaries or shell scripts.

esxi:vmkernel esxi:hostd esxi:cron
AN0311 Analytic 0311 DET0112

Monitoring modification and execution of user or system logon scripts such as in registry Run keys or startup folders.

WinEventLog:Security WinEventLog:Security WinEventLog:TaskScheduler
AN0324 Analytic 0324 DET0117

Creation or modification of Windows services or scheduled tasks with names or descriptions mimicking legitimate entries, followed by anomalous execution of untrusted binaries or LOLBAS.

WinEventLog:System WinEventLog:Security WinEventLog:Sysmon
AN0430 Analytic 0430 DET0151

Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell etw:Microsoft-Windows-Kernel-Process WinEventLog:TaskScheduler WinEventLog:TaskScheduler EDR:Telemetry
AN0582 Analytic 0582 DET0206

Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster.

kubernetes:apiserver kubernetes:events container:proxy
AN0645 Analytic 0645 DET0231

Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0806 Analytic 0806 DET0290

Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts.

macos:unifiedlog fs:fsusage
AN0807 Analytic 0807 DET0290

Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence.

esxi:hostd esxi:cron esxi:vmkernel
AN0943 Analytic 0943 DET0333

Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe.

WinEventLog:Security WinEventLog:Sysmon
AN0987 Analytic 0987 DET0347

Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.

esxi:vmkernel esxi:vmkernel esxi:hostd esxi:hostd
AN1115 Analytic 1115 DET0397

Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

macos:unifiedlog macos:unifiedlog macos:cron
AN1221 Analytic 1221 DET0441

Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1489 Analytic 1489 DET0540

Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1490 Analytic 1490 DET0540

Unusual long-running processes consuming high CPU cycles (e.g., via 'top' or 'ps') initiated via cron, shell scripts, or Docker. Connections to known mining pools or DNS over HTTPS usage as evasion.

auditd:SYSCALL NSM:Flow linux:cron
AN1507 Analytic 1507 DET0547

Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Application

Details

MITRE ID
DC0001
STIX ID
x-mitre-data-component--f42df6f0-6395-4f0c-9376-525a031f00c3
Analytics
21
Detection Strategies
15
Leaving Threaticon

This link opens an external site that isn't part of the platform.