{"id":"T1653","name":"Power Settings","url":"https://attack.mitre.org/techniques/T1653","tactics":["persistence"],"platforms":["Windows","Linux","macOS","Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0417","stix_id":"x-mitre-detection-strategy--40701244-5af5-477f-a9a7-ba661907f318","name":"Detection Strategy for Power Settings Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0417","analytics":[{"id":"AN1174","stix_id":"x-mitre-analytic--3234a537-0ad5-449f-87f4-25fd949c97e7","name":"Analytic 1174","description":"Monitor command execution of powercfg.exe with arguments modifying sleep, hibernate, or display timeouts. Abnormal or repeated modifications to power settings outside administrative baselines may indicate persistence attempts. Correlate process creation with registry and system configuration changes to build behavioral chains.","url":"https://attack.mitre.org/detectionstrategies/DET0417#AN1174","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"AllowedAdminTools","description":"Whitelist expected administrative scripts that legitimately modify power settings."},{"field":"TimeWindow","description":"Correlation period between powercfg.exe invocation and registry/policy changes."}],"live":true,"detection_strategies":["DET0417"],"techniques":["T1653"]},{"id":"AN1175","stix_id":"x-mitre-analytic--e3bbe2c4-615d-4847-93dc-b5857fc1b384","name":"Analytic 1175","description":"Detect execution of system utilities (systemctl, systemd-inhibit, systemdsleep) modifying sleep or hibernate behavior. Abnormal edits to system configuration files (e.g., /etc/systemd/sleep.conf) should be correlated with process execution to identify persistence techniques.","url":"https://attack.mitre.org/detectionstrategies/DET0417#AN1175","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of systemctl, loginctl, or systemd-inhibit commands related to sleep/hibernate","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"write: File modifications to /etc/systemd/sleep.conf or related power configuration files","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-path"}],"mutable_elements":[{"field":"KnownMaintenanceWindows","description":"Filter benign modifications during patching or system maintenance intervals."}],"live":true,"detection_strategies":["DET0417"],"techniques":["T1653"]},{"id":"AN1176","stix_id":"x-mitre-analytic--101d4e7f-4282-4fea-89be-e17d97ca0b91","name":"Analytic 1176","description":"Monitor pmset command executions altering sleep/hibernate/standby parameters. Unexpected modifications to /Library/Preferences/SystemConfiguration/com.apple.PowerManagement.plist or similar files should be correlated with process activity.","url":"https://attack.mitre.org/detectionstrategies/DET0417#AN1176","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process creation events where command line = pmset with arguments affecting sleep, hibernatemode, displaysleep","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"write: File modification to com.apple.PowerManagement.plist or related system preference files","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AdminWhitelists","description":"Allowlist expected pmset invocations by IT administrators for power policy enforcement."}],"live":true,"detection_strategies":["DET0417"],"techniques":["T1653"]}],"live":true,"version":"1.0","techniques":["T1653"]}],"sigma_rules":[{"id":"c172b7b5-f3a1-4af2-90b7-822c63df86cb","title":"Mask System Power Settings Via Systemctl","author":"Milad Cheraghi, Nasreddine Bencherchali","status":"experimental","level":"high","date":"2025-10-17","modified":null,"description":"Detects the use of systemctl mask to disable system power management targets such as suspend, hibernate, or hybrid sleep.\nAdversaries may mask these targets to prevent a system from entering sleep or shutdown states, ensuring their malicious processes remain active and uninterrupted.\nThis behavior can be associated with persistence or defense evasion, as it impairs normal system power operations to maintain long-term access or avoid termination of malicious activity.\n","references":["https://www.man7.org/linux/man-pages/man1/systemctl.1.html","https://linux-audit.com/systemd/faq/what-is-the-difference-between-systemctl-disable-and-systemctl-mask/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.persistence","attack.impact","attack.t1653"],"path":"rules/linux/process_creation/proc_creation_lnx_systemctl_mask_power_settings.yml","techniques":["T1653"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-20353","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}