Linux Detection Engineering - A Sequel on Persistence Mechanisms
ID: 72dafa05-50c4-5c38-b08e-11684480d1af
STIX ID: report--72dafa05-50c4-5c38-b08e-11684480d1af
Feed Name: Elastic Security Labs
This article (part three of a Linux Detection Engineering series) examines advanced Linux persistence techniques—such as SysV/Upstart init scripts, rc.local, MOTD scripts, udev-triggered execution, package manager hooks (APT/YUM/DNF), Git hooks and pager abuse, process capabilities, and system binary hijacking—mapping them to MITRE ATT&CK (e.g., T1037, T1546, T1546.016, T1548, T1554). It demonstrates how to set up and test these methods with the PANIX tool, then outlines layered detection strategies and hunts using SIEM/endpoint rules, ES|QL, and OSQuery, noting practical logging/timing constraints and emphasizing multi-layered defense.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
