1200KM / simulation
T1569.003 Systemctl — Attack Simulation
Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications. Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: `systemctl start`, `systemctl stop`, `systemctl enable`, `systemctl disable`, and…
Technique description
Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications. Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: `systemctl start`, `systemctl stop`, `systemctl enable`, `systemctl disable`, and…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Enumerate All systemd Services Using systemctl
Procedure 1e5be8d4-605a-4acb-8709-2f80b2d8ea95; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enable systemd Service for Persistence with Auto-Restart
Procedure 2fc6c0ab-4f88-4eb8-ab1b-f739fc22bba7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify Existing systemd Service to Execute Malicious Command
Procedure 6123928f-6389-4914-8d25-a5d69bd657fa; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerade Malicious Service as Legitimate System Service
Procedure 6fec8560-ff64-4bbf-bc79-734fea48f7ca; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create systemd Service Unit from /tmp (Unusual Location)
Procedure a1fa406e-2354-4a24-b6d6-94157e7564d4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Execute Command via Transient systemd Service (systemd-run)
Procedure a73a886f-23c5-4e8f-b1ab-b1bbc1f5e236; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create systemd Service Unit from /dev/shm (Unusual Location)
Procedure dce49381-a26b-4d95-bdfa-c607ffe8bee5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create and Enable a Malicious systemd Service Unit
Procedure e58c8723-5503-4533-b642-535cd20ec648; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.