Update linux_edit_cron_table_parameter.yml

This commit is contained in:
tccontre
2022-01-05 16:38:48 +01:00
committed by GitHub
parent 204670cbe1
commit cebc5ac4fd
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: The following analytic identifies a suspicious edit cronjobs parameter.
description: The following analytic identifies a suspicious cronjobs modification using crontab edit parameter.
This commandline parameter can be abuse by malware author, adversaries, and red
red teamers to add cronjob entry to their malicious code to execute to the schedule
they want. This event can also be executed by administrator or normal user for automation