Non-Root User Modifying Cron Files
Detects when a non-root user modifies, creates, or renames files within common cron directories or the main crontab file on Linux systems. This activity can indicate an attempt to establish persistence or schedule malicious tasks.
SentinelOne

