Skip to content

Hide Navigation Hide TOC

Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3)

The establishment of a task or job that will execute at a predefined time or based on specific triggers.

*Data Collection Measures: *

  • Windows Event Logs:
    • Event ID 4698 (Scheduled Task Created) – Detects the creation of new scheduled tasks.
    • Event ID 4702 (Scheduled Task Updated) – Identifies modifications to existing scheduled jobs.
    • Event ID 106 (TaskScheduler Operational Log) – Provides details about scheduled task execution.
  • Sysmon (Windows):
    • Event ID 1 (Process Creation) – Detects the execution of suspicious tasks started by schtasks.exe, at.exe, or taskeng.exe.
  • Linux/macOS Monitoring:
    • AuditD: Monitor modifications to /etc/cron*, /var/spool/cron/, and crontab files.
    • Syslog: Capture cron job execution logs from /var/log/cron.
    • OSQuery: Query the crontab and launchd tables for scheduled job configurations.
  • Endpoint Detection and Response (EDR) Tools:
    • Track scheduled task creation and modification events.
  • SIEM & XDR Detection Rules:
    • Monitor for scheduled jobs created by unusual users.
    • Detect tasks executing scripts from non-standard directories.
Cluster A Galaxy A Cluster B Galaxy B Level
Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3) mitre-data-component 1
At - T1053.002 (f3d95a1f-bba2-44ce-9af7-37866cd63fd0) Attack Pattern Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3) mitre-data-component 1
Container Orchestration Job - T1053.007 (1126cab1-c700-412f-a510-61f4937bb096) Attack Pattern Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3) mitre-data-component 1
Cron - T1053.003 (2acf44aa-542f-4366-b4eb-55ef5747759c) Attack Pattern Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3) mitre-data-component 1
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3) mitre-data-component 1
Systemd Timers - T1053.006 (a542bac9-7bc1-4da7-9a09-96f69e23cc21) Attack Pattern Scheduled Job Creation (f42df6f0-6395-4f0c-9376-525a031f00c3) mitre-data-component 1
Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern At - T1053.002 (f3d95a1f-bba2-44ce-9af7-37866cd63fd0) Attack Pattern 2
Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern Container Orchestration Job - T1053.007 (1126cab1-c700-412f-a510-61f4937bb096) Attack Pattern 2
Cron - T1053.003 (2acf44aa-542f-4366-b4eb-55ef5747759c) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2
Scheduled Task - T1053.005 (005a06c6-14bf-4118-afa0-ebcd8aebb0c9) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2
Systemd Timers - T1053.006 (a542bac9-7bc1-4da7-9a09-96f69e23cc21) Attack Pattern Scheduled Task/Job - T1053 (35dd844a-b219-4e2b-a6bb-efa9a75995a9) Attack Pattern 2