Compliance Node Overview
MITRE ATT&CK T1053.003 (Cron) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths. An adversary may use cron in Linux or Unix environments to execute programs at system startup or on a scheduled basis for Persistence. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1053/003/
SHA-256 integrity: 52c7e6f1cbde1480e20c9e8fdac821dce2a88e3acc8c9fcd0217270ef174a12a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1053.003: Cron (https://attack.mitre.org/techniques/T1053/003/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.