<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Persistence on RGROSEC</title><link>https://aegrah.github.io/categories/persistence.html</link><description>Recent content in Persistence on RGROSEC</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © Ruben Groenewoud</copyright><lastBuildDate>Tue, 25 Feb 2025 12:00:00 +0200</lastBuildDate><atom:link href="https://aegrah.github.io/categories/persistence/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms</title><link>https://aegrah.github.io/post/2025-02-25-linux-detection-engineering-grand-finale-on-linux-persistence-mechanisms.html</link><pubDate>Tue, 25 Feb 2025 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2025-02-25-linux-detection-engineering-grand-finale-on-linux-persistence-mechanisms.html</guid><description>
In the fifth and final part of the Linux Persistence Detection Engineering series, we bring the journey to its grand finale by exploring some of the most obscure, creative, and complex persistence mechanisms. Building on the foundational concepts covered in previous publications, this final installment focuses on techniques rooted in the Linux boot process, authentication systems, inter-process communication, and core utilities.
We begin with GRUB-based persistence and the manipulation of initramfs, demonstrating both manual modifications and automated approaches using Dracut.</description></item><item><title>Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms</title><link>https://aegrah.github.io/post/2025-02-11-linux-detection-engineering-approach-the-summit-on-persistence-mechanisms.html</link><pubDate>Tue, 11 Feb 2025 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2025-02-11-linux-detection-engineering-approach-the-summit-on-persistence-mechanisms.html</guid><description>
In the fourth part of the Linux Persistence Detection Engineering series, I continue exploring advanced Linux persistence techniques, expanding on the foundation set in previous publications.
This latest installment delves into additional creative and complex methods adversaries use to maintain persistence on Linux systems. We explore the abuse of Pluggable Authentication Modules (PAM), specifically how pam_exec can be leveraged to execute malicious code during authentication events. We also analyze installer package manipulation via RPM and DPKG, where lifecycle scripts are weaponized to establish persistence through package installations and updates.</description></item><item><title>Linux Detection Engineering - A Continuation on Persistence Mechanisms</title><link>https://aegrah.github.io/post/2025-01-27-linux-detection-engineering-continuation-on-persistence-mechanisms.html</link><pubDate>Mon, 27 Jan 2025 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2025-01-27-linux-detection-engineering-continuation-on-persistence-mechanisms.html</guid><description>
In the third part of the Linux Persistence Detection Engineering series, I continue exploring advanced Linux persistence techniques, expanding on the foundation set in previous publications.
This latest installment dives into more creative and complex persistence methods, providing security researchers and defenders with a deeper understanding of how adversaries maintain access on Linux systems. We explore techniques such as dynamic linker hijacking, where adversaries manipulate the dynamic linker through LD_PRELOAD to execute malicious code persistently.</description></item><item><title>Linux Detection Engineering - A sequel on persistence mechanisms</title><link>https://aegrah.github.io/post/2024-08-29-linux-detection-engineering-sequel-on-persistence-mechanisms.html</link><pubDate>Thu, 29 Aug 2024 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2024-08-29-linux-detection-engineering-sequel-on-persistence-mechanisms.html</guid><description>
In this second part of the Linux Persistence Detection Engineering series, I explore the world of more advanced Linux persistence techniques. This part builds upon the knowledge obtained from the previous persistence blog dubbed &amp;quot;Linux Detection Engineering - A Primer on Persistence Mechanisms&amp;quot;. This sequel aims to equip defenders and security researchers with a more comprehensive understanding of Linux persistence. With the help of PANIX, a Linux persistence tool I developed, we will simulate these techniques, analyze the logs and observe detection opportunities.</description></item><item><title>Linux Detection Engineering - A primer on persistence mechanisms</title><link>https://aegrah.github.io/post/2024-08-21-linux-detection-engineering-primer-on-persistence-mechanisms.html</link><pubDate>Fri, 23 Aug 2024 12:00:00 +0200</pubDate><guid>https://aegrah.github.io/post/2024-08-21-linux-detection-engineering-primer-on-persistence-mechanisms.html</guid><description>
In this first installment of the Linux Persistence Detection Engineering series, I delve into Linux persistence mechanisms, exploring both common and complex techniques to enhance the knowledge of defenders and security researchers. I examine how these persistence methods operate, how to set them up, and most importantly, how to detect and hunt for them effectively. With the help of PANIX, a Linux persistence tool I developed, I’ll demonstrate practical examples and detection strategies, ensuring you gain a solid understanding of these crucial techniques.</description></item></channel></rss>