Rule Info
Name
Potential Crontab Persistence via CLI
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects command lines attempting to install a crontab persistence via cli by echoing a cron schedule and piping it to 'crontab -' via stdin.
Attackers may use this technique to establish persistence on a compromised system by scheduling malicious tasks to run at regular intervals.
Date
2026-08-07 00:00:00
Modified
None
Id
8385d87a-34c2-4c7b-8a6c-ab3909eb54a0
Tags
attack.persistence attack.execution attack.privilege-escalation attack.t1053.003
Type
Nextron Sigma feed only (private)
