T1543.002: Technique T1543.002
Adversaries may leverage living-off-the-land techniques (T1543.002) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 1
•
Windows: 0
•
Linux: 1
•
macOS: 0
Living-off-the-Land Matrix for T1543.002
Across 1 verified binariesLinux1 payloads
systemctl
Systemctl controls the systemd system and service manager. Sudo privileges on systemctl allow linking or creating transient unit files that execute root commands upon service start.
Sample Attack Vector:
systemctl link /tmp/malicious.service && systemctl start maliciousCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point