BIOC Informational

Modification of systemd service files

An attacker may create or modify systemd service unit files to establish persistence between reboots.

Module:
Platform Analytics
Agent event type:
File
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create or Modify System Process: Systemd Service (T1543.002)
Indicator:

File action type = write , create AND file path =~ (^/etc/systemd/system/|^/usr/lib/systemd/system/|^/run/systemd/system/|/lib/systemd/system/|\.config/systemd/user/|^/etc/systemd/user/|\.local/share/systemd/user/|^/run/systemd/user/|^/usr/lib/systemd/user/).*\.service Host host os = linux

Preventable: yes