T1543.002Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1543.002: Technique T1543.002

Adversaries may leverage living-off-the-land techniques (T1543.002) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 1
Windows: 0
Linux: 1
macOS: 0

Living-off-the-Land Matrix for T1543.002

Across 1 verified binaries
Linux1 payloads

systemctl

Systemctl controls the systemd system and service manager. Sudo privileges on systemctl allow linking or creating transient unit files that execute root commands upon service start.

Sample Attack Vector:
systemctl link /tmp/malicious.service && systemctl start malicious
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point