Linux Service Reload/Start via systemctl or service Command Execution
Identifies Linux process executions invoking service control commands with start or reload keywords.
- Product
- linux
- Service
- auditd
- Author
- Jakob Weinzettl, oscd.community, CheraghiMilad (SigmaHQ), DRL 1.1
- Published
- 2019-09-23
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
Identifies execution of command-line processes containing the strings 'systemctl' or 'service' along with 'reload' or 'start'. This behavior matters because attackers often reconfigure, start, or reload services to establish persistence or apply changes without needing a reboot. The rule relies on Linux auditd telemetry capturing process execution events (EXECVE) and string matching within the command arguments.
Reporting behind it
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux Service Reload/Start via systemctl or service Command Execution
id: 5846ef01-c9f3-47e9-bd20-5dc08232d8f0
status: test
description: Identifies execution of command-line processes containing the strings 'systemctl' or 'service' along with 'reload' or 'start'. This behavior matters because attackers often reconfigure, start, or reload services to establish persistence or apply changes without needing a reboot. The rule relies on Linux auditd telemetry capturing process execution events (EXECVE) and string matching within the command arguments.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.002/T1543.002.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/execve/lnx_auditd_susp_service_reload_or_restart.yml
author: Jakob Weinzettl, oscd.community, CheraghiMilad, Huntrule Team
date: 2019-09-23
modified: 2025-03-03
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1543.002
logsource:
product: linux
service: auditd
detection:
selection:
type: EXECVE
a0|contains:
- systemctl
- service
a1|contains:
- reload
- start
condition: selection
falsepositives:
- Installation of legitimate service.
- Legitimate reconfiguration of service.
- Command line contains daemon-reload.
level: low
license: DRL-1.1
related:
- id: 2625cc59-0634-40d0-821e-cb67382a3dd7
type: derived