Linux Detection Engineering - The Grand Finale on Linux Persistence
ID: a75ebcde-dce7-530e-922b-ba893c1857e1
STIX ID: report--a75ebcde-dce7-530e-922b-ba893c1857e1
Feed Name: Elastic Security Labs
This final installment of a Linux persistence detection engineering series details how to simulate, detect, and hunt for advanced Linux persistence mechanisms across GRUB (T1542), initramfs via manual modification and Dracut (T1542), PolicyKit (T1543), D-Bus (T1543/T1574), and NetworkManager dispatcher scripts (T1546), leveraging the PANIX toolkit to demonstrate setup, provide detection rules and ES|QL/OSQuery hunts, and outline safe revert steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
