Rule Info
Name
Logging Service Stopped or Disabled via Systemctl
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects use of systemctl to stop, kill, mask, or disable common Linux logging and auditing services (rsyslog, syslog-ng, auditd, systemd-journald).
Attackers and ransomware use this to silence audit trails before encryption or exfiltration.
Masking a service additionally prevents it from being restarted by other processes.
Date
2026-08-19 00:00:00
Modified
None
Id
3a9f1c2e-5b4d-4e8a-c6d7-2f1e0b5a3c9d
Tags
attack.defense-impairment attack.t1685.004
Type
Nextron Sigma feed only (private)
