Rule Info
Name
Suspicious Crontab Pipeline Injection
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Tim Rauch (Nextron Systems)
Description
Detects suspicious crontab pipeline injection patterns where an attacker reads the
existing crontab with crontab -l, appends a malicious entry via echo, and writes it
back using crontab - (stdin mode), as legitimate crontab edits are done
interactively via crontab -e rather than from stdin.
Date
2026-09-30 00:00:00
Modified
None
Id
fcd17954-b1d7-4b48-82db-31e335bab774
Tags
attack.execution attack.persistence attack.privilege-escalation attack.t1053.003
Type
Nextron Sigma feed only (private)
