Umbra Wiki technique technique/T1569.003
Back to wiki

T1569.003 — Systemctl

provenance: imported · ATT&CK: T1569.003

T1569.003: Systemctl

MITRE ATT&CK® Enterprise technique

Tactics Execution
Platforms Linux
Permissions required
Version 1.0
Parent technique T1569

Description

Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications.

Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: systemctl start, systemctl stop, systemctl enable, systemctl disable, and systemctl status.(Citation: Red Hat Systemctl 2022)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1569/003
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/