mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update linux_edit_cron_table_parameter.yml
This commit is contained in:
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
|
||||
type: Hunting
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a suspicious edit cronjobs parameter.
|
||||
description: The following analytic identifies a suspicious cronjobs modification using crontab edit parameter.
|
||||
This commandline parameter can be abuse by malware author, adversaries, and red
|
||||
red teamers to add cronjob entry to their malicious code to execute to the schedule
|
||||
they want. This event can also be executed by administrator or normal user for automation
|
||||
|
||||
Reference in New Issue
Block a user