Masquerading as the Linux crond process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading: Masquerade Task or Service (T1036.004)
Severity
Low
Description
Copies a file and renames it as crond.
Attacker's Goals
Attackers may masquerade as the crond executable.
Investigative actions
Verify that this isn't IT activity.
Look for other hosts executing similar commands.
Variations
Was this helpful?
