Linux Service Reload/Start via systemctl or service Command Execution

Identifies Linux process executions invoking service control commands with start or reload keywords.

FreeReviewedSigma · Low · v3
Product
linux
Service
auditd
Author
Jakob Weinzettl, oscd.community, CheraghiMilad (SigmaHQ), DRL 1.1
Published
2019-09-23
Updated
2026-07-31
title: Linux Service Reload/Start via systemctl or service Command Execution
id: 5846ef01-c9f3-47e9-bd20-5dc08232d8f0
status: test
description: Identifies execution of command-line processes containing the strings 'systemctl' or 'service' along with 'reload' or 'start'. This behavior matters because attackers often reconfigure, start, or reload services to establish persistence or apply changes without needing a reboot. The rule relies on Linux auditd telemetry capturing process execution events (EXECVE) and string matching within the command arguments.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.002/T1543.002.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/execve/lnx_auditd_susp_service_reload_or_restart.yml
author: Jakob Weinzettl, oscd.community, CheraghiMilad, Huntrule Team
date: 2019-09-23
modified: 2025-03-03
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1543.002
logsource:
  product: linux
  service: auditd
detection:
  selection:
    type: EXECVE
    a0|contains:
      - systemctl
      - service
    a1|contains:
      - reload
      - start
  condition: selection
falsepositives:
  - Installation of legitimate service.
  - Legitimate reconfiguration of service.
  - Command line contains daemon-reload.
level: low
license: DRL-1.1
related:
  - id: 2625cc59-0634-40d0-821e-cb67382a3dd7
    type: derived