// MITRE ATT&CK
T1569.003 · Systemctl
Sub-technique of T1569 · System Services.
Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications. Adversaries may use systemctl to execute comm...
How to detect & mitigate it
Detecting Systemctl starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1053.005
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1053.007
Container Orchestration Job T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron
Scheduled Task T1047
Windows Management Instrumentation T1129
Shared Modules T1059.007
JavaScript T1053.007
Container Orchestration Job T1559.002
Dynamic Data Exchange T1204.002
Malicious File T1053.003
Cron
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.