Compliance Node Overview
MITRE ATT&CK T1546.017 (Udev Rules) is an Enterprise Persistence and Privilege Escalation sub-technique of T1546 (Event Triggered Execution). Adversaries may maintain persistence through executing malicious content triggered using udev rules. Udev is the Linux kernel device manager that dynamically manages device nodes, handles access to pseudo-device files in the /dev directory, and responds to hardware events, such as when external devices like hard drives or keyboards are plugged in or removed. Udev uses rule files with match keys to specify the conditions a hardware event must meet and action keys to define the actions that should follow. Affected platforms: Linux. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-06, IA-09, SI-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/017/
SHA-256 integrity: 6ccff120b6cb1a49fe8b7a1bc19a03adfe918ca11ef8a7b57ecbc191ad76b0ab
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1546.017: Udev Rules (https://attack.mitre.org/techniques/T1546/017/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access