Linux service management via systemctl/service (start or reload)
Identifies Linux process executions invoking service control commands with start or reload keywords.
FreeUnreviewedSigmalowv1
linux-service-management-via-systemctl-service-start-or-reload-2625cc59
title: Linux service management via systemctl/service (start or reload)
id: 5846ef01-c9f3-47e9-bd20-5dc08232d8f0
status: test
description: This rule flags Linux executions of the systemctl or service command where the command line includes start or reload. Service control actions are commonly used by attackers to persist access, apply changes, or restart components after compromise. The detection relies on auditd EXECVE telemetry capturing command-line arguments in process start events.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.002/T1543.002.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/execve/lnx_auditd_susp_service_reload_or_restart.yml
author: Jakob Weinzettl, oscd.community, CheraghiMilad, Huntrule Team
date: 2019-09-23
modified: 2025-03-03
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1543.002
logsource:
product: linux
service: auditd
detection:
selection:
type: EXECVE
a0|contains:
- systemctl
- service
a1|contains:
- reload
- start
condition: selection
falsepositives:
- Installation of legitimate service.
- Legitimate reconfiguration of service.
- Command line contains daemon-reload.
level: low
license: DRL-1.1
related:
- id: 2625cc59-0634-40d0-821e-cb67382a3dd7
type: derived
What it detects
This rule flags Linux executions of the systemctl or service command where the command line includes start or reload. Service control actions are commonly used by attackers to persist access, apply changes, or restart components after compromise. The detection relies on auditd EXECVE telemetry capturing command-line arguments in process start events.
Known false positives
- Installation of legitimate service.
- Legitimate reconfiguration of service.
- Command line contains daemon-reload.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.