LoFP LoFP / legitimate system administrators or software packages may place custom generators in systemd generator directories during system configuration or application deployment. filter based on known software installations and verified administrative activity.

Techniques

Sample rules

Linux File Creation In System Generator Directory

Description

The following analytic detects potential persistence using a systemd generator on Linux, which involves creating a malicious script or binary that is typically executed during the system’s boot process. Systemd generators are typically placed in directories like /lib/systemd/system-generators/, where they are run early in the boot sequence to dynamically generate or modify unit files that control system services. By placing a custom generator in this directory, an attacker can ensure their code is executed each time the system starts, allowing them to maintain access or control even after reboots.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Endpoint.Filesystem where

Filesystem.action IN ("created", "modified")
Filesystem.file_path="*/lib/systemd/system-generators/*"

by Filesystem.file_path Filesystem.file_name Filesystem.user Filesystem.dest
   Filesystem.action Filesystem.process_guid Filesystem.process_id


| `drop_dm_object_name(Filesystem)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_file_creation_in_system_generator_directory_filter`