Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Persistence, Privilege Escalation

T1543.002 Systemd Service

Sub-technique of T1543 Create or Modify System Process

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources.(Citation: Linux man-pages: systemd January 2014) Systemd is the default initialization (init) system on many Linux distributions…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.