Skip to content

Cron Jobs

Evidence: Cron Jobs
Description: Collect Cron Jobs
Category: System
Platform: macos
Short Name: cronj
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers cron jobs information from the macOS system. This data is essential for understanding system activity, detecting persistence, and investigating scheduled task misuse.

This collector gathers structured data about cron jobs.

FieldDescriptionExample
EventEventExample value
MinuteMinuteExample value
HourHourExample value
DayOfMonthDay Of MonthExample value
MonthMonthExample value
DayOfWeekDay Of WeekExample value
CommandCommandExample value
PathPathExample value

This collector queries the crontab table via osquery; if a path is present for an entry, the underlying file is collected.

This evidence is crucial for forensic investigations as it reveals scheduled tasks that can indicate persistence mechanisms, data exfiltration schedules, or malicious automation.