kevmap

TechniquesT1569 › T1569.003

T1569.003 Systemctl

execution — Linux · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1569.003
0
KEV CVEs mapped here
<p>Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications.</p><p>Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: systemctl start, systemctl stop, systemctl enable, systemctl disable, and systemctl status.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1569.003

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1569) 4

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton · 2021-06-30 (modified 2022-11-15) · logsource: product=windows service=printservice-admin · 4e64668a-4da1-49f5-a8df-9e2d5b866718
Detects events of driver load errors in print service logs that could be a sign of successful exploitation attempts of print spooler vulnerability CVE-2021-1675
Techniques: T1569
CVE tags: CVE-2021-1675
Psexec Execution mediumtest
Author: omkar72 · 2020-10-30 (modified 2023-02-28) · logsource: product=windows category=process_creation · 730fc21b-eaff-474b-ad23-90fd265d4988
Detects user accept agreement execution in psexec commandline
Techniques: T1569T1021
Author: INIT_6 · 2021-07-02 (modified 2022-10-05) · logsource: product=windows service=security · 8fe1c584-ee61-444b-be21-e9054b229694
Detects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
Techniques: T1569
CVE tags: CVE-2021-1675CVE-2021-34527
Author: Florian Roth (Nextron Systems) · 2021-07-01 (modified 2022-10-09) · logsource: product=windows service=printservice-operational · f34d942d-c8c4-4f1f-b196-22471aecf10a
Detects driver load events print service operational log that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675
Techniques: T1569
CVE tags: CVE-2021-1675