Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0375 — Detection Strategy for T1546.017 - Udev Rules (Linux)
DET0375

Detection Strategy for T1546.017 - Udev Rules (Linux)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1056 Analytic 1056
Linux

Monitor for creation or modification of udev rules files in key directories (/etc/udev/rules.d/, /lib/udev/rules.d/, /usr/lib/udev/rules.d/). Look for RUN+= or IMPORT keys invoking suspicious binaries or scripts. Correlate this with process execution from systemd-udevd context, and file writes near udev reload/restart events. Combine this with unexpected background process spawning from udevd-related forks.

auditd:SYSCALL chmod, write, create, open auditd:SYSCALL execve auditd:CONFIG_CHANGE udev rule reload or trigger command executed
[UdevRulePath] Path to udev rules (may vary by distro or user configuration)
[SuspiciousRunPattern] Regex or string pattern to flag suspicious command executions in RUN+=
[TimeWindow] Max interval between rule change and execution to correlate activity
[ParentProcess] Expected parent of RUN-invoked commands (e.g., systemd-udevd)

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0375
STIX ID
x-mitre-detection-strategy--408fb023-a9d7-473c-8db8-a7d3c66eded7
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.