Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0231 — Behavioral Detection of Systemd Timer Abuse for Scheduled Execution
DET0231

Behavioral Detection of Systemd Timer Abuse for Scheduled Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0645 Analytic 0645
Linux

Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root.

auditd:SYSCALL creat, open, write on /etc/systemd/system and /usr/lib/systemd/system auditd:SYSCALL execve logging for /usr/bin/systemctl and systemd-run linux:osquery file_events
[TimerIntervalThreshold] The interval threshold used to determine if a newly created timer is unusually frequent or immediate (e.g., < 5 minutes).
[ParentProcessID] Whether the child process has a parent PID of 1, indicating systemd as the invoker. Can be tuned to include known benign cases.
[UserContext] User under which the timer/service is created or executed (e.g., root vs. non-root).
[TimerCreationPath] The path where the timer or service file is created; system-wide vs. user space can be scoped.

Detected Techniques

1

Details

MITRE ID
DET0231
STIX ID
x-mitre-detection-strategy--7578b2e3-2b9c-491d-9157-699a4bd6a136
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.