IT Forensics · Linux

Forensic Analysis of systemd Units and Services – Persistence Mechanisms in Modern Linux Systems

On modern Linux systems, systemd manages services, mount points, devices and other resources via so-called units. These unit files can also be used to run programmes automatically and permanently at system start-up.

Enquire without obligation

For forensic purposes, service units created outside the regular system configuration are of particular relevance, as they may represent a common persistence mechanism for unauthorised software.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We systematically analyse all installed systemd units, identify atypical or subsequently added service definitions, and map these to the corresponding executable files and processes.

Typical areas of application

Detection of unauthorised persistence mechanisms
Investigation of retrofitted services
Analysis of malware persistence via systemd
Reconstruction of the system configuration history
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a systemd unit analysis works

Once the backup has been completed, all existing systemd unit files are systematically recorded and compared with known standard configurations for the respective distribution. Any units that appear unusual or atypical are examined separately and matched to the corresponding executable files.

Why is the analysis of systemd units relevant from a forensic perspective?

systemd service units are among the most common mechanisms for running malware continuously and automatically at system start-up. Systematic checks for them are therefore a key component of many incident response investigations.

As systemd configurations can be complex and spread across several directories, a complete inventory requires knowledge of the relevant search paths and prioritisation rules.

Frequently Asked Questions

Where are systemd unit files stored?+
These include, amongst other things, system-wide and user-specific directories, the exact order of priority of which depends on the distribution in question.
Can attackers create their own systemd units?+
Yes, with sufficient permissions, it is possible to create your own service units in order to run malware on a permanent basis.
How are atypical units identified?+
By comparing them with known standard configurations for the respective distribution, and by checking the build date and the executable files referenced.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of systemd units and services"? LanCologne can assist you in securing digital evidence in a manner that meets legal standards, as well as in the transparent analysis of relevant Linux artefacts.

Get in touch now