logo

Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms

ID: 1d50fd1b-0697-5b62-9f7e-a2b62399dba7

STIX ID: report--1d50fd1b-0697-5b62-9f7e-a2b62399dba7

Feed Name: Elastic Security Labs

Date Published: 2025-02-11

Date Updated: 2026-04-27

...
...

This fourth entry in the Linux Persistence Detection Engineering series explores advanced Linux persistence tactics—T1556.003 (malicious PAM modules and pam_exec), T1546.016 (DPKG/RPM installer lifecycle scripts), and T1610 (malicious Docker containers)—demonstrated via the PANIX framework, and provides practical detection, hunting, and rollback guidance to help defenders identify and remediate these techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.