Systemctl

T1569.003

Sub-technique of T1569 System Services.View on attack.mitre.org

About this technique

Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications.

Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: `systemctl start`, `systemctl stop`, `systemctl enable`, `systemctl disable`, and `systemctl status`.

Detection rules0

Rules on DetectionCode tagged with T1569.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupTeamTNT

TeamTNT has created system services to execute cryptocurrency mining software.

Software1

Used byProcedure example
MalwareCanisterWorm

CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service.

References1

  1. Red Hat Systemctl 2022 Open source
    Damon Garn. (2022, May 17). How to use systemctl to manage Linux services. Retrieved March 18, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.