Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0073 — Detection Strategy for System Services: Systemctl
DET0073

Detection Strategy for System Services: Systemctl

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0200 Analytic 0200
Linux

Abuse of systemctl to execute commands or manage systemd services. Defender perspective: correlate suspicious service creation or modification with execution of systemctl subcommands such as start, enable, or status. Detect cases where systemctl is used to load services from unusual locations (e.g., /tmp, /dev/shm) or where new service units are created outside of expected administrative workflows.

auditd:EXECVE execution of systemctl with subcommands start, stop, enable, disable auditd:SYSCALL open/write of .service unit files auditd:EXECVE systemctl spawning managed processes auditd:CONFIG_CHANGE creation or modification of systemd services
[MonitoredPaths] Paths to monitor for service unit files, typically /etc/systemd/system and /usr/lib/systemd/system. Adversaries may use uncommon locations such as /tmp.
[SuspiciousSubcommands] Focus on systemctl subcommands start, enable, or daemon-reload when used outside expected change windows.
[CorrelationWindow] Time window to correlate service file modification with subsequent systemctl execution.

Detected Techniques

1

Execution (1)

Details

MITRE ID
DET0073
STIX ID
x-mitre-detection-strategy--8a9b730a-b290-40ce-b182-dbcb06fbad3d
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.