Power Settings T1653

Tactic: Persistence

Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines. When a computer enters a dormant state, some or all software and hardware may cease to operate which can disrupt malicious activity.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (2 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine1contains 1 mask, hibernate.target, hybrid-sleep.target
Image1ends_with 1/systemctl

Top indicator values (5 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
mask
1
CommandLinecontains
hibernate.target
1
CommandLinecontains
hybrid-sleep.target
1
CommandLinecontains
suspend.target
1
Imageends_with
/systemctl
14

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Linux

Domain: Endpoint

Sigma 1 rule