Detection rules › Sigma

Mask System Power Settings Via Systemctl

Status
experimental
Severity
high
Log source
category process_creation, product linux
Author
Milad Cheraghi, Nasreddine Bencherchali
Source
github.com/SigmaHQ/sigma

Detects the use of systemctl mask to disable system power management targets such as suspend, hibernate, or hybrid sleep. Adversaries may mask these targets to prevent a system from entering sleep or shutdown states, ensuring their malicious processes remain active and uninterrupted. This behavior can be associated with persistence or defense evasion, as it impairs normal system power operations to maintain long-term access or avoid termination of malicious activity.

Known false positives

  • Unlikely

MITRE ATT&CK coverage

TacticTechniques
Persistence

Telemetry coverage

PlatformRecord / event type
LinuxEvent ID 1: Process Create

Rule body

title: Mask System Power Settings Via Systemctl
id: c172b7b5-f3a1-4af2-90b7-822c63df86cb
status: experimental
description: |
    Detects the use of systemctl mask to disable system power management targets such as suspend, hibernate, or hybrid sleep.
    Adversaries may mask these targets to prevent a system from entering sleep or shutdown states, ensuring their malicious processes remain active and uninterrupted.
    This behavior can be associated with persistence or defense evasion, as it impairs normal system power operations to maintain long-term access or avoid termination of malicious activity.
author: Milad Cheraghi, Nasreddine Bencherchali
date: 2025-10-17
references:
    - https://www.man7.org/linux/man-pages/man1/systemctl.1.html
    - https://linux-audit.com/systemd/faq/what-is-the-difference-between-systemctl-disable-and-systemctl-mask/
tags:
    - attack.persistence
    - attack.impact
    - attack.t1653
logsource:
    category: process_creation
    product: linux
detection:
    selection_systemctl:
        Image|endswith: '/systemctl'
        CommandLine|contains: ' mask'
    selection_power_options:
        CommandLine|contains:
            - 'suspend.target'
            - 'hibernate.target'
            - 'hybrid-sleep.target'
    condition: all of selection_*
falsepositives:
    - Unlikely
level: high

Stages and Predicates

Stage 0: condition

all of selection_*

Stage 1: selection_systemctl

selection_systemctl:
    Image|endswith: '/systemctl'
    CommandLine|contains: ' mask'

Stage 2: selection_power_options

selection_power_options:
    CommandLine|contains:
        - 'suspend.target'
        - 'hibernate.target'
        - 'hybrid-sleep.target'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • mask
  • hibernate.target
  • hybrid-sleep.target
  • suspend.target
field:"CommandLine" kind:match
Imageends_with
  • /systemctl
field:"Image" kind:ends_with value:"/systemctl"