logo

Linux Detection Engineering - A Sequel on Persistence Mechanisms

ID: 72dafa05-50c4-5c38-b08e-11684480d1af

STIX ID: report--72dafa05-50c4-5c38-b08e-11684480d1af

Feed Name: Elastic Security Labs

Date Published: 2024-08-30

Date Updated: 2026-04-27

...
...

This article (part three of a Linux Detection Engineering series) examines advanced Linux persistence techniques—such as SysV/Upstart init scripts, rc.local, MOTD scripts, udev-triggered execution, package manager hooks (APT/YUM/DNF), Git hooks and pager abuse, process capabilities, and system binary hijacking—mapping them to MITRE ATT&CK (e.g., T1037, T1546, T1546.016, T1548, T1554). It demonstrates how to set up and test these methods with the PANIX tool, then outlines layered detection strategies and hunts using SIEM/endpoint rules, ES|QL, and OSQuery, noting practical logging/timing constraints and emphasizing multi-layered defense.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.