Lesser Known Linux Persistence Mechanisms

Lesser Known Linux Persistence Mechanisms

Source: YouTube · John Hammond · published Aug 22, 2025 · 22:30

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation explores both common and lesser-known Linux persistence mechanisms that adversaries use to maintain access to compromised systems 1:16, with the speaker explaining persistence as techniques used by attackers to maintain footholds and backdoors for ongoing access 1:42.

Key Takeaways:
• Beyond basic methods like SSH keys and cron jobs, SSH proxy commands can be configured in SSH config files to execute arbitrary commands during connections 11:45
• TCP wrapped services (/etc/hosts.allow and /etc/hosts.deny) can be exploited to trigger backdoors when specific services connect 13:00
• PAM (Pluggable Authentication Module) degradation attacks allow attackers to create backdoor authentication modules that accept universal passwords 14:28
• Userland rootkits like Prism can use ICMP traffic for covert command and control communications, bypassing typical network monitoring 16:48
• Linux kernel modules like Reptile can manipulate file system operations, forcing the kernel to return false data even when files are modified 18:06

The presentation concludes with mention of the Panics tool from Elastic, which provides a framework for testing and researching these persistence mechanisms 20:22.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hey, quick context as to what this video is. This is the recording of my talk in presentation from Black Hat USA titled Lesser Known Linux Persistence Mechanisms. Now, I had given this presentation with my day job, Huntress. And let me please say this is not a sponsored video. Huntress did not sponsor me or pay or anything to get this video uploaded. I guess you know they pay my salary. But I just genuinely thought, hey, this is a cool presentation. I hope the technical work, the concepts, the material, I hope that's educational and valuable for you. But the inspiration from this talk is just, hey, you know what? We've got a new Linux agent out in beta. We have a Linux agent for our EDR platform. That's super cool. This is just off the tales of us announcing the uh now Jen Easterly, the fo…