
Lesser Known Linux Persistence Mechanisms
Source: YouTube · John Hammond · published Aug 22, 2025 · 22:30
This presentation explores both common and lesser-known Linux persistence mechanisms that adversaries use to maintain access to compromised systems 1:16, with the speaker explaining persistence as techniques used by attackers to maintain footholds and backdoors for ongoing access 1:42.
Key Takeaways:
• Beyond basic methods like SSH keys and cron jobs, SSH proxy commands can be configured in SSH config files to execute arbitrary commands during connections 11:45
• TCP wrapped services (/etc/hosts.allow and /etc/hosts.deny) can be exploited to trigger backdoors when specific services connect 13:00
• PAM (Pluggable Authentication Module) degradation attacks allow attackers to create backdoor authentication modules that accept universal passwords 14:28
• Userland rootkits like Prism can use ICMP traffic for covert command and control communications, bypassing typical network monitoring 16:48
• Linux kernel modules like Reptile can manipulate file system operations, forcing the kernel to return false data even when files are modified 18:06
The presentation concludes with mention of the Panics tool from Elastic, which provides a framework for testing and researching these persistence mechanisms 20:22.
Sources:
- 1:16 Introduction to Linux persistence mechanisms
- 1:42 Definition of persistence in context of MITRE ATT&CK
- 11:45 SSH proxy commands technique
- 13:00(https://www.yout
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hey, quick context as to what this video is. This is the recording of my talk in presentation from Black Hat USA titled Lesser Known Linux Persistence Mechanisms. Now, I had given this presentation with my day job, Huntress. And let me please say this is not a sponsored video. Huntress did not sponsor me or pay or anything to get this video uploaded. I guess you know they pay my salary. But I just genuinely thought, hey, this is a cool presentation. I hope the technical work, the concepts, the material, I hope that's educational and valuable for you. But the inspiration from this talk is just, hey, you know what? We've got a new Linux agent out in beta. We have a Linux agent for our EDR platform. That's super cool. This is just off the tales of us announcing the uh now Jen Easterly, the fo…