// MITRE ATT&CK
T1053.007 · Container Orchestration Job
Sub-technique of T1053 · Scheduled Task/Job.
Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code. Container orchestration jobs run these automated tasks at a specific date and time, similar to cron jobs on a Li...
How to detect & mitigate it
Detecting Container Orchestration Job starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1053.005
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron T1559.001
Component Object Model
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron T1559.001
Component Object Model
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.