Scheduled Task/Job: Systemd Timers T1053.006

Tactics: Execution, Persistence, Privilege Escalation

Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd timers are unit files with file extension .timer that control services. Timers can be set to run on a calendar event or after a time span relative to a starting point. They can be used as an alternative to Cron in Linux environments. Systemd timers may be activated remotely via the systemctl command line utility, which operates over SSH.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 6 rules share fields, values, and exclusions.

Fields filtered most (12 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
TargetFilename3wildcard 2, in 1, starts_with 1*/etc/systemd/system*, */etc/systemd/user*, */lib/systemd/system*, /etc/*, /etc/cron.allow
CommandLine2in 2* enable *, * start *, *reenable*, *reload*, *restart*
EventType2in 2creation, rename, open
file.extension2eq 1, in 1timer, service
process_name2in 2service, systemctl
container.id1starts_with 1?
event.type1ne 1deletion
file.name1in 1.bash_aliases, .bash_login, .bash_logout
file_name1ends_with 1.service
host.os.type1eq 1
proctitle1in 1*reenable*, *reload*, *restart*
sourcetype1eq 1auditd

Top indicator values (80 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinein
*service *
22
CommandLinein
*systemctl *
22
CommandLinein
* enable *
1
CommandLinein
* start *
1
CommandLinein
*reenable*
1
CommandLinein
*reload*
1
CommandLinein
*restart*
1
EventTypein
creation
234
EventTypein
rename
227
EventTypein
open
17
TargetFilenamewildcard
/etc/systemd/system/*
25
TargetFilenamewildcard
/etc/systemd/user/*
24
TargetFilenamewildcard
/home/*/.config/systemd/user/*
25
TargetFilenamewildcard
/home/*/.local/share/systemd/user/*
25
TargetFilenamewildcard
/lib/systemd/system/*
25
TargetFilenamewildcard
/root/.config/systemd/user/*
25
TargetFilenamewildcard
/root/.local/share/systemd/user/*
25
TargetFilenamewildcard
/usr/lib/systemd/system/*
25
TargetFilenamewildcard
/usr/lib/systemd/user/*
24
TargetFilenamewildcard
/usr/local/lib/systemd/system/*
25
process_namein
service
27
process_namein
systemctl
26
TargetFilenamein
*/etc/systemd/system*
1
TargetFilenamein
*/etc/systemd/user*
1
TargetFilenamein
*/lib/systemd/system*
1
TargetFilenamein
*/lib/systemd/user*
1
TargetFilenamein
*/run/systemd/system*
1
TargetFilenamein
*/run/systemd/user*
1
TargetFilenamein
*/usr/lib/systemd/system*
1
TargetFilenamein
*/usr/lib/systemd/user*
1

Exclusions (103 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagein
./usr/bin/podman
1
Imagein
/bin/autossl_check
1
Imagein
/bin/chef-client
1
Imagein
/bin/dnf
1
Imagein
/bin/dnf-automatic
1
Imagein
/bin/dockerd
1
Imagein
/bin/dpkg
1
Imagein
/bin/dpkg-divert
1
Imagein
/bin/install
1
Imagein
/bin/microdnf
1
Imagein
/bin/pacman
1
Imagein
/bin/pamac-daemon
1
Imagein
/bin/podman
1
Imagein
/bin/puppet
1
Imagein
/bin/rpm
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 2 rules

Splunk 4 rules