{
  "node_id": "mitre-attack-t1053-scheduled-task-job",
  "title": "MITRE ATT&CK T1053: Scheduled Task/Job (Enterprise Tactic TA0002 - Execution / TA0003 - Persistence / TA0004 - Privilege Escalation)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1053 (Scheduled Task/Job) is an Enterprise Execution and Persistence and Privilege Escalation technique. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). ATT&CK documents 5 sub-techniques: T1053.002 At; T1053.003 Cron; T1053.005 Scheduled Task; T1053.006 Systemd Timers; T1053.007 Container Orchestration Job. Affected platforms: Windows, Linux, macOS, Containers. MITRE-documented mitigations include M1018 User Account Management, M1028 Operating System Configuration, M1022 Restrict File and Directory Permissions, M1026 Privileged Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, CM-06, CM-07.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}