{"id":"T1053.007","name":"Container Orchestration Job","url":"https://attack.mitre.org/techniques/T1053/007","tactics":["execution","persistence","privilege-escalation"],"platforms":["Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0206","stix_id":"x-mitre-detection-strategy--a1e17bbb-73d6-48d5-b0ab-1350189b0ecd","name":"Detection of Malicious Kubernetes CronJob Scheduling","url":"https://attack.mitre.org/detectionstrategies/DET0206","analytics":[{"id":"AN0582","stix_id":"x-mitre-analytic--f2c03ef0-cd36-42b8-9c2d-e25a3b1b8b1c","name":"Analytic 0582","description":"Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster.","url":"https://attack.mitre.org/detectionstrategies/DET0206#AN0582","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:apiserver","channel":"verb=create, resource=cronjobs, group=batch","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"kubernetes-apiserver"},{"name":"kubernetes:events","channel":"container start/stop activity via Docker, containerd, or CRI-O","data_component":"DC0072","data_component_name":"Container Creation","log_source_slug":"kubernetes-events"},{"name":"container:proxy","channel":"outbound/inbound network activity from spawned pods","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"container-proxy"}],"mutable_elements":[{"field":"NamespaceScope","description":"Kubernetes namespace the job is deployed to—scoping this to known trusted namespaces may reduce noise."},{"field":"ImageRepository","description":"The container image registry or repository the job pulls from—can be filtered by trusted registries."},{"field":"ScheduleWindow","description":"Time window or frequency of CronJob execution (e.g., ‘@hourly’)—jobs running at odd hours may be suspicious."},{"field":"ExecutionCommand","description":"The command or entrypoint executed by the Job—unexpected shell commands or interpreters may warrant inspection."}],"live":true,"detection_strategies":["DET0206"],"techniques":["T1053.007"]}],"live":true,"version":"1.0","techniques":["T1053.007"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}