T1569.003 — Systemctl
T1569.003: Systemctl
MITRE ATT&CK® Enterprise technique
| Tactics | Execution |
| Platforms | Linux |
| Permissions required | — |
| Version | 1.0 |
| Parent technique | T1569 |
Description
Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications.
Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: systemctl start, systemctl stop, systemctl enable, systemctl disable, and systemctl status.(Citation: Red Hat Systemctl 2022)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1569/003
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/