Product
medium
advisory
Detection of Linux Persistence via Systemd Generators
1 rule 2 TTPsThis detection identifies potential persistence on Linux systems by monitoring for unauthorized file creation or modification within the /lib/systemd/system-generators/ directory, which executes during the boot sequence.
systemd
persistence
linux
1r
2t
low
advisory
Potential Proxy Execution via Systemd-run on Linux
1 rule 3 TTPsThis brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.
Acronis Cyber Protect +46
defense-evasion
execution
linux
1r
3t