Sub-technique of T1569 System Services.View on attack.mitre.org
Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications.
Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: `systemctl start`, `systemctl stop`, `systemctl enable`, `systemctl disable`, and `systemctl status`.
Rules on DetectionCode tagged with T1569.003.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupTeamTNT | TeamTNT has created system services to execute cryptocurrency mining software. |
| Used by | Procedure example |
|---|---|
| MalwareCanisterWorm | CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.