Linux Persistence File Creation Targeting sysmon.py and systemd user service

Alerts on creation of user persistence files under sysmon.py or systemd user service paths by a process running from /python3.

FreeReviewedSigma · High · v5
Product
linux
Category
file_event
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-03-30
Updated
2026-07-31

ATT&CK techniques

Initial Access → Priv Esc
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags file creation events where the executing image path contains '/python3' and the target filename ends with either '/.config/sysmon/sysmon.py' or '/.config/systemd/user/sysmon.service'. Such persistence-related drops matter because attackers can use Python-launched activity to write a backdoor entrypoint or a user-level systemd service for recurring execution. The detection relies on Linux file event telemetry that includes the process image path and the targeted filename.

Related detections9 linkedT1195.002 — drag to rearrange
Linux Process Creation Indicators for LiteLLM Backdoored Package Activity (v1.82.7/v1.82.8)
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Malicious Koske Persistence via Systemd Service and Shell Profile Hijack (via process_creation)
Suspicious Linux CoinMiner Watchdog Staging in Shared Memory (via process_creation)
Suspicious systemd Service Persistence Creation (via process_creation)
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Malicious PowerShell Download from bullethost.cloud Staging Server
Linux Persistence File Creation Targeting sysmon.py and systemd user service
Pivot detection · T1195.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.