{"id":"T1569.003","name":"Systemctl","url":"https://attack.mitre.org/techniques/T1569/003","tactics":["execution"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0073","stix_id":"x-mitre-detection-strategy--8a9b730a-b290-40ce-b182-dbcb06fbad3d","name":"Detection Strategy for System Services: Systemctl","url":"https://attack.mitre.org/detectionstrategies/DET0073","analytics":[{"id":"AN0200","stix_id":"x-mitre-analytic--756d5795-ef61-4115-80d2-f2e7440dff56","name":"Analytic 0200","description":"Abuse of systemctl to execute commands or manage systemd services. Defender perspective: correlate suspicious service creation or modification with execution of systemctl subcommands such as start, enable, or status. Detect cases where systemctl is used to load services from unusual locations (e.g., /tmp, /dev/shm) or where new service units are created outside of expected administrative workflows.","url":"https://attack.mitre.org/detectionstrategies/DET0073#AN0200","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"execution of systemctl with subcommands start, stop, enable, disable","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"open/write of .service unit files","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"systemctl spawning managed processes","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"auditd:CONFIG_CHANGE","channel":"creation or modification of systemd services","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"auditd-config-change"}],"mutable_elements":[{"field":"MonitoredPaths","description":"Paths to monitor for service unit files, typically /etc/systemd/system and /usr/lib/systemd/system. Adversaries may use uncommon locations such as /tmp."},{"field":"SuspiciousSubcommands","description":"Focus on systemctl subcommands start, enable, or daemon-reload when used outside expected change windows."},{"field":"CorrelationWindow","description":"Time window to correlate service file modification with subsequent systemctl execution."}],"live":true,"detection_strategies":["DET0073"],"techniques":["T1569.003"]}],"live":true,"version":"1.0","techniques":["T1569.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}