Linux Detection Engineering - A Continuation on Persistence Mechanisms
ID: fec9a0c6-2a98-544a-9681-164042cf8560
STIX ID: report--fec9a0c6-2a98-544a-9681-164042cf8560
Feed Name: Elastic Security Labs
This article, part of a Linux Detection Engineering series, explores key Linux persistence techniques—T1574.006 (dynamic linker hijacking via LD_PRELOAD), T1547.006 (kernel modules and extensions) with rootkit context (T1014), T1505.003 (web shells in PHP/Python/CGI), and T1098.004 (SSH authorized_keys abuse via system users)—showing how to simulate them with the PANIX tool, identify artifacts, and craft detections using prebuilt rules, ES|QL/OSQuery hunts, and practical guidance, including cleanup/revert steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
