Back to updates
UpdatedJul 28, 2026

persisthunt — Updated!

Linux Persistence Detection, Hunting and Artifact Collection script

Share

Linux Persistence Detection, Hunting and Artifact Collection

Summary

persisthunt.sh helps speed up investigations by collecting targeted persistence-related artifacts and highlighting suspicious patterns commonly associated with Linux persistence techniques.

The script assists in persistence detection, threat hunting, and artifact collection across well-known Linux persistence mechanisms. Findings are categorized into three levels - High, Low, and Informational based on confidence and severity. Examples include suspicious autorun entries referencing /tmp/, /home/, /dev/tcp, curl, or detection of active bind/reverse shells.

It is designed as a flexible foundation that defenders can customize for their environments by adding or removing detection logic and keywords. The output can be large and may require environment-specific analysis, but it is also suitable for review and summarization using LLMs or AI agents.

Usage

Run as root user and redirect output to a file

sudo persisthunt.sh > output.log

Run on a remote host via SSH

ssh [email protected] 'bash -s' < persisthunt.sh > output.log 2>&1

Example Detections

=== [HIGH] Active reverse shell ===
bob      3889906  0.0  0.0   2800  1848 pts/2    S+   06:38   0:00 sh -i

=== [HIGH] Active bind shell ===
LISTEN 0      1                                     0.0.0.0:4444  0.0.0.0:* users:(("python3",pid=3891687,fd=3))
bob      3891687  0.7  0.3  19540 12320 pts/3    S+   06:41   0:00 python3 -c exec("""import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind(("0.0.0.0",4444));s1.listen(1);c,a=s1.accept(); while True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())""")

=== [HIGH] eBPF programs with raw network sockets (possible BPFdoor persistence) ===
PID: 3903559, Executable: bpfdoorpoc, Stack trace: /proc/3903559/stack:[<0>] packet_recvmsg+0x6e/0x5c0

=== [LOW] Recent ELF binary in tmp/home/hidden dirs ===
/var/tmp/.test

Techniques

Categories