Compliance Node Overview
MITRE ATT&CK T1053.006 (Systemd Timers) is an Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd timers are unit files with file extension .timer that control services. Timers can be set to run on a calendar event or after a time span relative to a starting point. They can be used as an alternative to Cron in Linux environments. Systemd timers may be activated remotely via the systemctl command line utility, which operates over SSH. Affected platforms: Linux. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1018 User Account Management, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1053/006/
SHA-256 integrity: 7a2120fef67cbff4a7304952374f4fde833b424200932b1561b78d25d5409c76
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1053.006: Systemd Timers (https://attack.mitre.org/techniques/T1053/006/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access