logo

Linux Detection Engineering - A Continuation on Persistence Mechanisms

ID: fec9a0c6-2a98-544a-9681-164042cf8560

STIX ID: report--fec9a0c6-2a98-544a-9681-164042cf8560

Feed Name: Elastic Security Labs

Date Published: 2025-01-27

Date Updated: 2026-04-27

...
...

This article, part of a Linux Detection Engineering series, explores key Linux persistence techniques—T1574.006 (dynamic linker hijacking via LD_PRELOAD), T1547.006 (kernel modules and extensions) with rootkit context (T1014), T1505.003 (web shells in PHP/Python/CGI), and T1098.004 (SSH authorized_keys abuse via system users)—showing how to simulate them with the PANIX tool, identify artifacts, and craft detections using prebuilt rules, ES|QL/OSQuery hunts, and practical guidance, including cleanup/revert steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.