Linux Detection Engineering - A primer on persistence mechanisms
ID: d19ef9d5-bfc8-584f-b150-db3127ec4b38
STIX ID: report--d19ef9d5-bfc8-584f-b150-db3127ec4b38
Feed Name: Elastic Security Labs
This article in Elastic’s Linux Detection Engineering series surveys core Linux persistence TTPs—cron/at (T1053), systemd services/timers/generators (T1543/T1053), shell profile modifications (T1546.004), XDG autostart (T1547.013), SUID/SGID (T1548.001), sudoers changes (T1548.003), account and SSH key manipulation (T1098/T1136/T1098.004), and bind/reverse shells (T1059.004)—and shows how to emulate them with the PANIX tool. It maps techniques to MITRE ATT&CK and provides practical detection and hunting guidance using Elastic prebuilt SIEM and endpoint rules, File Integrity Monitoring, ES|QL, and OSQuery to identify and investigate persistence across Linux environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
