LoFP
/
legitimate modification of crontab
t1053
t1053.003
linux
sigma
Techniques
t1053
t1053.003
Sample rules
Modifying Crontab
source
:
sigma
technicques
:
t1053
t1053.003
Description
Detects suspicious modification of crontab file.
Detection logic
condition
:
keywords
keywords
:
-
REPLACE