{"id":"T1053.006","name":"Systemd Timers","url":"https://attack.mitre.org/techniques/T1053/006","tactics":["execution","persistence","privilege-escalation"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0231","stix_id":"x-mitre-detection-strategy--7578b2e3-2b9c-491d-9157-699a4bd6a136","name":"Behavioral Detection of Systemd Timer Abuse for Scheduled Execution","url":"https://attack.mitre.org/detectionstrategies/DET0231","analytics":[{"id":"AN0645","stix_id":"x-mitre-analytic--a80f58c9-deb2-45ed-a8fb-4f3df5082874","name":"Analytic 0645","description":"Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root.","url":"https://attack.mitre.org/detectionstrategies/DET0231#AN0645","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"creat, open, write on /etc/systemd/system and /usr/lib/systemd/system","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve logging for /usr/bin/systemctl and systemd-run","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"file_events","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"TimerIntervalThreshold","description":"The interval threshold used to determine if a newly created timer is unusually frequent or immediate (e.g., < 5 minutes)."},{"field":"ParentProcessID","description":"Whether the child process has a parent PID of 1, indicating systemd as the invoker. Can be tuned to include known benign cases."},{"field":"UserContext","description":"User under which the timer/service is created or executed (e.g., root vs. non-root)."},{"field":"TimerCreationPath","description":"The path where the timer or service file is created; system-wide vs. user space can be scoped."}],"live":true,"detection_strategies":["DET0231"],"techniques":["T1053.006"]}],"live":true,"version":"1.0","techniques":["T1053.006"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}