Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms
ID: 1d50fd1b-0697-5b62-9f7e-a2b62399dba7
STIX ID: report--1d50fd1b-0697-5b62-9f7e-a2b62399dba7
Feed Name: Elastic Security Labs
This fourth entry in the Linux Persistence Detection Engineering series explores advanced Linux persistence tactics—T1556.003 (malicious PAM modules and pam_exec), T1546.016 (DPKG/RPM installer lifecycle scripts), and T1610 (malicious Docker containers)—demonstrated via the PANIX framework, and provides practical detection, hunting, and rollback guidance to help defenders identify and remediate these techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
