Lesser Known Linux Persistence Mechanisms

Lesser Known Linux Persistence Mechanisms

🎙 John Hammond 👥 2.2M 📅 August 22, 2025 ⏱ 22 min 👁 21K 📄 expert opinion 🧭 2026-08-17
Available in: English (current) Français

Keywords

persistenceLinuxbackdoorSSHrootkit

Summary

In this talk from Black Hat USA, John Hammond, Principal Security Researcher at Huntress, presents lesser-known Linux persistence mechanisms. He begins by acknowledging common methods like adding backdoor users, SSH keys, cron jobs, systemd services, and shell rc files, but quickly moves to more esoteric techniques. He discusses the PROMPT_COMMAND variable and trap commands for executing payloads on shell interaction, and highlights SSH configuration options like ProxyCommand and the ability to specify custom authorized keys files. He then covers TCP wrappers (libwrap) and how they can be abused to trigger backdoors via services like SNMP. PAM degradation attacks are explained, where a custom PAM module allows authentication with a backdoor password, referencing a recent malware called ‘The Plague’. He introduces userland rootkits like Prism, which communicates over ICMP, and kernel rootkits like Reptile, which can manipulate file reads to hide persistence. Finally, he recommends the ‘Panics’ tool from Elastic for testing persistence mechanisms. The talk emphasizes the importance of looking beyond conventional persistence methods and provides practical examples for detection and research.

172 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into lesser-known Linux persistence techniques, offering practical examples and real-world context. The argumentation is solid, based on the speaker’s experience and recent security incidents. The presentation is well-structured, moving from basic to advanced methods, and includes actionable information for security professionals. However, some techniques are only briefly mentioned without deep technical details, and the talk is more of an overview than an in-depth analysis.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates good scientific rigor by referencing specific tools and recent malware campaigns, such as ‘The Plague’ and the ‘Panics’ tool from Elastic. However, he does not provide formal citations or links to external sources within the talk, relying on his expertise and the audience’s familiarity with the topics. The title accurately reflects the content, and the talk is well-aligned with the stated purpose. The speaker also mentions his affiliation with Huntress, but clearly states that the video is not sponsored, maintaining transparency.

168 words

Title / Content Match

The title accurately reflects the content, focusing on lesser-known persistence mechanisms in Linux.

Quality & Reliability

8/10

The content is presented by a recognized security researcher with practical experience, and includes references to real-world tools and recent malware campaigns. However, it is based on personal expertise and conference talk, lacking formal citations or peer review.

Key Moments

Cited Sources

  • CodeCrafters — Affiliate link mentioned in description, not directly cited in talk.
  • CyberDefenders — Affiliate link mentioned in description, not directly cited in talk.
  • Newsletter — Link to John Hammond's newsletter, mentioned in description.
  • OpenVPN — Affiliate link mentioned in description, not directly cited in talk.
  • Just Hacking Training — Link to training platform, mentioned in description.

Concurring Sources

  • MITRE ATT&CK — Framework for understanding persistence techniques.
  • GTFOBins — Resource for abusing binaries for persistence.

Contribution & Novelties

The video provides a valuable overview of lesser-known Linux persistence mechanisms, filling a gap in common knowledge. It highlights techniques like TCP wrappers, PAM degradation, and rootkits that are often overlooked. The speaker’s practical experience and references to recent malware add credibility. The talk encourages security professionals to think beyond conventional persistence methods.

Pour aller plus loin :

  • MITRE ATT&CK Persistence — Official framework for persistence techniques.
  • Linux Kernel Module Programming Guide — Resource for understanding LKM rootkits.
  • PAM documentation — Official documentation for Pluggable Authentication Modules.
  • GTFOBins — List of Unix binaries that can be abused for privilege escalation and persistence.
  • Panics tool — Elastic’s tool for testing persistence mechanisms.

111 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates a well-rounded presentation that is both informative and credible, though it may not dive deeply into every technique.

Reliability 8/10