Power Settings T1653
Tactic: Persistence
Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines. When a computer enters a dormant state, some or all software and hardware may cease to operate which can disrupt malicious activity.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 1 rule share fields, values, and exclusions.
Fields filtered most (2 distinct)
These fields appear most often in rule filters.
Top indicator values (5 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint