Techniques › T1653 › AN1175
AN1175 Analytic 1175
Linux · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detect execution of system utilities (systemctl, systemd-inhibit, systemdsleep) modifying sleep or hibernate behavior. Abnormal edits to system configuration files (e.g., /etc/systemd/sleep.conf) should be correlated with process execution to identify persistence techniques.</p>
- Detects
- T1653 Power Settings
- Part of
- DET0417 Detection Strategy for Power Settings Abuse
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| auditd:SYSCALL | execve: Execution of systemctl, loginctl, or systemd-inhibit commands related to sleep/hibernate | DC0064 Command Execution |
| auditd:PATH | write: File modifications to /etc/systemd/sleep.conf or related power configuration files | DC0061 File Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
KnownMaintenanceWindows | Filter benign modifications during patching or system maintenance intervals. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Mapped |