Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse

Alerts on auditd PATH events referencing /sysrq or /sysrq-trigger, indicating possible Linux Magic SysRq abuse.

FreeReviewedSigma · Medium · v3
Product
linux
Service
auditd
Author
Milad Cheraghi (SigmaHQ), DRL 1.1
Published
2025-05-23
Updated
2026-07-31

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule flags execution events with a PATH ending in /sysrq, /sysctl.conf, or /sysrq-trigger, which can indicate attempts to enable and trigger Linux Magic SysRq behavior. Adversaries with sufficient privileges may use SysRq to manipulate or destabilize systems, for example by triggering disruptive actions through /proc/sysrq-trigger, potentially impacting incident response. Detection relies on auditd telemetry capturing PATH values associated with these filesystem locations.

Related detections9 linkedT1059.004 — drag to rearrange
Suspicious Shell Spawned by ActiveMQ Java Process
Suspicious Bad Apples Reverse Shell via socat pty
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Possible Akira Ransomware VM Shutdown via vim-cmd
Possible Ransomware Pre-Encryption VM Termination via esxcli
Malicious Shell Payload Piped from curl to zsh
Possible Bitbucket Pre-Auth RCE via git archive exec Null-Byte Injection (CVE-2022-36804) (via webserver)
Malicious TeamTNT Docker Gatling Gun Initialization Script (via process_creation)
Suspicious Shell Spawned by PostgreSQL Server Process (via process_creation)
Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Pivot detection · T1059.004 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.