Skip to content

Hide Navigation Hide TOC

Mask System Power Settings Via Systemctl (c172b7b5-f3a1-4af2-90b7-822c63df86cb)

Detects the use of systemctl mask to disable system power management targets such as suspend, hibernate, or hybrid sleep. Adversaries may mask these targets to prevent a system from entering sleep or shutdown states, ensuring their malicious processes remain active and uninterrupted. This behavior can be associated with persistence or defense evasion, as it impairs normal system power operations to maintain long-term access or avoid termination of malicious activity.

Cluster A Galaxy A Cluster B Galaxy B Level
Power Settings - T1653 (ea071aa0-8f17-416f-ab0d-2bab7e79003d) Attack Pattern Mask System Power Settings Via Systemctl (c172b7b5-f3a1-4af2-90b7-822c63df86cb) Sigma-Rules 1