( 03 )NOTES/SYSTEMD_PERSISTENCE
SYNC0x4A1F
notes/systemd-persistence
linux

Systemd Persistence

Quick notes on systemd services and timers as Linux persistence mechanisms.

2026-09-12
1 min read
linuxpersistencesystemdservicesenumerationred-team

Systemd Persistence Locations#

Common locations: /etc/systemd/system/ /usr/lib/systemd/system/ /lib/systemd/system/ Custom services under /etc/systemd/system/ deserve attention.
Systemd timers can trigger services at scheduled intervals. Useful commands: systemctl list-timers --all systemctl list-unit-files --type=service
systemd enumeration
>systemctl list-unit-files --type=service
>systemctl list-timers --all
>systemctl --type=service --state=running
>ls -la /etc/systemd/system/
>
Findings
INFO
Suspicious Services Look for: • Unknown services • Services pointing to unusual paths • Executables under /tmp or user-writable directories • Unexpected services running as root • Recently created or modified unit files • Suspicious ExecStart commands
inspect a service
>systemctl cat <service-name>
>systemctl show <service-name> -p ExecStart -p User
>

Takeaway#

When investigating Linux persistence, don't just list running services. Inspect how they start, what they execute, where the executable lives, and which user runs it.

Back to Notesnote: systemd-persistence