{"id":"T1546.017","name":"Udev Rules","url":"https://attack.mitre.org/techniques/T1546/017","tactics":["persistence","privilege-escalation"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0375","stix_id":"x-mitre-detection-strategy--408fb023-a9d7-473c-8db8-a7d3c66eded7","name":"Detection Strategy for T1546.017 - Udev Rules (Linux)","url":"https://attack.mitre.org/detectionstrategies/DET0375","analytics":[{"id":"AN1056","stix_id":"x-mitre-analytic--c1167779-9df4-4387-b777-4da097c6b033","name":"Analytic 1056","description":"Monitor for creation or modification of udev rules files in key directories (/etc/udev/rules.d/, /lib/udev/rules.d/, /usr/lib/udev/rules.d/). Look for RUN+= or IMPORT keys invoking suspicious binaries or scripts. Correlate this with process execution from systemd-udevd context, and file writes near udev reload/restart events. Combine this with unexpected background process spawning from udevd-related forks.","url":"https://attack.mitre.org/detectionstrategies/DET0375#AN1056","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"chmod, write, create, open","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:CONFIG_CHANGE","channel":"udev rule reload or trigger command executed","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-config-change"}],"mutable_elements":[{"field":"UdevRulePath","description":"Path to udev rules (may vary by distro or user configuration)"},{"field":"SuspiciousRunPattern","description":"Regex or string pattern to flag suspicious command executions in RUN+="},{"field":"TimeWindow","description":"Max interval between rule change and execution to correlate activity"},{"field":"ParentProcess","description":"Expected parent of RUN-invoked commands (e.g., systemd-udevd)"}],"live":true,"detection_strategies":["DET0375"],"techniques":["T1546.017"]}],"live":true,"version":"1.0","techniques":["T1546.017"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}