Linux持久化溯源
原名:analyzing-persistence-mechanisms-in-linux
扫描 Linux 持久化机制(crontab、systemd、LD_PRELOAD、SSH 后门),并与 auditd 日志关联生成安装时间线,用于事件响应或威胁狩猎。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3 / 5
内容概览
Adversaries establish persistence on Linux systems through crontab jobs, systemd service/timer units, LD PRELOAD library injection, shell profile modifications (.bashrc, .profile), SSH authorized keys backdoors, and init script manipulation. This skill scans for all known persistence vectors, checks file timestamps and integrity, and correlates findings with auditd logs to build a timeline of persistence installation. - When investigating security incidents that require analyzing persistence mechanisms in linux - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Root or sudo access on target Linux system (or forensic image) - auditd configured with file watch rules on persistence paths - Python 3.8+ with standard librar…