Suspicious Crontab Pipeline Injection

Rule Info

Name
Suspicious Crontab Pipeline Injection
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Tim Rauch (Nextron Systems)
Description
Detects suspicious crontab pipeline injection patterns where an attacker reads the existing crontab with crontab -l, appends a malicious entry via echo, and writes it back using crontab - (stdin mode), as legitimate crontab edits are done interactively via crontab -e rather than from stdin.
Date
2026-09-30 00:00:00
Modified
None
Id
fcd17954-b1d7-4b48-82db-31e335bab774
Tags
attack.execution attack.persistence attack.privilege-escalation attack.t1053.003
Type
Nextron Sigma feed only (private)

Rule History