Rare persistence techniques. Part 4
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Rare persistence techniques. Part 4
Also read about: Zabbix Agent, TimeProvider, COM Hijacking, WMICLNT.
5️⃣ Systemd Generator
A Systemd Generator is an executable file that systemd runs during system boot (or when daemon-reload is executed) to dynamically create unit files for services, targets, and mount points. Attackers use this mechanism for stealthy persistence, since generators run with root privileges before the main services start and are rarely checked by administrators.
Key directories:
• /etc/systemd/system-generators/*
• /usr/local/lib/systemd/system-generators/*
• /lib/systemd/system-generators/* (or /usr/lib/systemd/system-generators/)
😐 Persistence mechanism:
1. The attacker places an executable file in one of the key directories — a script or binary file (usually with a disguised name, for example systemd-cp-generator).
2. On every system boot or when systemctl daemon-reload is executed — systemd runs all discovered generators.
3. The generator can: create its own service in /run/systemd/system/ and enable it, overwrite units of existing services (especially via /run/systemd/generator.early/, where the priority is higher than that of /etc/systemd/system/), disable critical security tools, execute a payload directly.
😮 Recommendations:
Since generators run before monitoring systems, the primary method is monitoring the file system for the creation and modification of files in the generator directories.
1. File system monitoring — first of all, track the creation and modification of files in the listed directories. Use auditd, since it works at the kernel level and can trigger even during early boot.
2. Integrity control — periodically compare the hash sums of files in the generator directories against reference values.
3. Restricting permissions — prohibit regular users and unprivileged processes from writing to these directories.
4. Generator analysis — check for non-standard or recently appeared generators, especially if they are not from legitimate packages (openvpn, systemd-rc-local-generator, etc.).
That’s it for this series of posts — that’s all for now 😉
#ir #dfir #tips
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



