Linux File Creation In System Generator Directory — Detection Rule
The following analytic detects potential persistence using a systemd generator on Linux, which involves creating a malicious script or binary that is typically executed during the system's boot process. Systemd generators are typically placed in directories like /lib/systemd/system-generators/, where they are run early in the boot sequence to dynamically generate or modify unit files that control system services. By placing a custom generator in this directory, an attacker can ensure their code is executed each time the system starts, allowing them to maintain access or control even after reboots.