The establishment of a task or job that will execute at a predefined time or based on specific triggers.
*Data Collection Measures: *
schtasks.exe, at.exe, or taskeng.exe./etc/cron*, /var/spool/cron/, and crontab files./var/log/cron.crontab and launchd tables for scheduled job configurations.| Name | Channel |
|---|---|
| esxi:cron | execution of scheduled job |
| esxi:hostd | task creation events |
| esxi:vmkernel | Startup script and task execution logs |
| kubernetes:apiserver | verb=create, resource=cronjobs, group=batch |
| linux:cron | Scheduled execution of unknown or unusual script/binary |
| linux:osquery | crontab, systemd_timers |
| linux:osquery | file_events |
| linux:syslog | Execution of non-standard script or binary by cron |
| macos:cron | cron/launchd |
| macos:osquery | launchd_jobs |
| macos:osquery | file_events - cron, launchd |
| macos:unifiedlog | process: crontab edits, launch of cron job |
| Scheduled Job | None |
| WinEventLog:Security | EventCode=4698 |
| WinEventLog:Security | EventCode=4699 |
| WinEventLog:TaskScheduler | EventCode=106 |