logo

Linux Detection Engineering - A primer on persistence mechanisms

ID: d19ef9d5-bfc8-584f-b150-db3127ec4b38

STIX ID: report--d19ef9d5-bfc8-584f-b150-db3127ec4b38

Feed Name: Elastic Security Labs

Date Published: 2024-08-21

Date Updated: 2026-04-27

...
...

This article in Elastic’s Linux Detection Engineering series surveys core Linux persistence TTPs—cron/at (T1053), systemd services/timers/generators (T1543/T1053), shell profile modifications (T1546.004), XDG autostart (T1547.013), SUID/SGID (T1548.001), sudoers changes (T1548.003), account and SSH key manipulation (T1098/T1136/T1098.004), and bind/reverse shells (T1059.004)—and shows how to emulate them with the PANIX tool. It maps techniques to MITRE ATT&CK and provides practical detection and hunting guidance using Elastic prebuilt SIEM and endpoint rules, File Integrity Monitoring, ES|QL, and OSQuery to identify and investigate persistence across Linux environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.