IT Forensics · Linux
Forensic Analysis of systemd Units and Services – Persistence Mechanisms in Modern Linux Systems
On modern Linux systems, systemd manages services, mount points, devices and other resources via so-called units. These unit files can also be used to run programmes automatically and permanently at system start-up.
For forensic purposes, service units created outside the regular system configuration are of particular relevance, as they may represent a common persistence mechanism for unauthorised software.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We systematically analyse all installed systemd units, identify atypical or subsequently added service definitions, and map these to the corresponding executable files and processes.
Typical areas of application
This is how a systemd unit analysis works
Once the backup has been completed, all existing systemd unit files are systematically recorded and compared with known standard configurations for the respective distribution. Any units that appear unusual or atypical are examined separately and matched to the corresponding executable files.
Why is the analysis of systemd units relevant from a forensic perspective?
systemd service units are among the most common mechanisms for running malware continuously and automatically at system start-up. Systematic checks for them are therefore a key component of many incident response investigations.
As systemd configurations can be complex and spread across several directories, a complete inventory requires knowledge of the relevant search paths and prioritisation rules.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of systemd units and services"? LanCologne can assist you in securing digital evidence in a manner that meets legal standards, as well as in the transparent analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of cron jobs – systematically examining scheduled tasks
- Forensic analysis of systemd timers – Evaluating a modern alternative to traditional cron
- Forensic analysis of init.d scripts – Checking traditional system boot mechanisms
- Forensic identification of autostart mechanisms in Linux – An overview of all relevant persistence methods