Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0417 — Detection Strategy for Power Settings Abuse
DET0417

Detection Strategy for Power Settings Abuse

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1174 Analytic 1174
Windows

Monitor command execution of powercfg.exe with arguments modifying sleep, hibernate, or display timeouts. Abnormal or repeated modifications to power settings outside administrative baselines may indicate persistence attempts. Correlate process creation with registry and system configuration changes to build behavioral chains.

WinEventLog:Security EventCode=4688
[AllowedAdminTools] Whitelist expected administrative scripts that legitimately modify power settings.
[TimeWindow] Correlation period between powercfg.exe invocation and registry/policy changes.
AN1175 Analytic 1175
Linux

Detect execution of system utilities (systemctl, systemd-inhibit, systemdsleep) modifying sleep or hibernate behavior. Abnormal edits to system configuration files (e.g., /etc/systemd/sleep.conf) should be correlated with process execution to identify persistence techniques.

auditd:SYSCALL execve: Execution of systemctl, loginctl, or systemd-inhibit commands related to sleep/hibernate auditd:PATH write: File modifications to /etc/systemd/sleep.conf or related power configuration files
[KnownMaintenanceWindows] Filter benign modifications during patching or system maintenance intervals.
AN1176 Analytic 1176
macOS

Monitor pmset command executions altering sleep/hibernate/standby parameters. Unexpected modifications to /Library/Preferences/SystemConfiguration/com.apple.PowerManagement.plist or similar files should be correlated with process activity.

macos:unifiedlog Process creation events where command line = pmset with arguments affecting sleep, hibernatemode, displaysleep macos:unifiedlog write: File modification to com.apple.PowerManagement.plist or related system preference files
[AdminWhitelists] Allowlist expected pmset invocations by IT administrators for power policy enforcement.

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0417
STIX ID
x-mitre-detection-strategy--40701244-5af5-477f-a9a7-ba661907f318
Analytics
3
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.