Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PANIX — Customizable Linux Persistence Tool for Security Research and Detection Engineering. | Kitploit
Tools/GitHubGitHub/aegrah/panix
Privilege EscalationPersistence MechanismsPost-ExploitationPenetration TestingRed TeamingRemote Access ToolContainer Escape
GitHubaegrah/panix

PANIX

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

View Repository
876102177 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

PANIX logo

PANIX - Persistence Against *NIX

PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.

Features

PANIX provides a versatile suite of features for simulating and researching Linux persistence mechanisms.

FeatureDescriptionRootUser
At Job PersistenceImplements persistence by adding entries to system jobs.✅✅
Authorized KeysAdds a public key to the authorized_keys file for SSH access.✅✅
Backdoor UserCreates a backdoor user with UID=0 (root privileges).✅❌
Backdoor System UserBackdoor a system user (SSH access to news/nobody).✅❌
Backdoored /etc/passwdDirectly adds a malicious user entry to /etc/passwd.✅❌
Backdoored /etc/init.dEstablishes persistence via SysVinit (/etc/init.d).✅❌
Backdoored /etc/rc.localEstablishes persistence via run control (/etc/rc.local).✅❌
Bind ShellRuns a pre-compiled/LOLBin bind shell for remote access.✅✅
Capabilities BackdoorAdds specific capabilities to binaries to maintain persistence.✅❌
Cron Job PersistenceSets up cron jobs to ensure persistence across reboots.✅✅
Create UserCreates a new user account on the system.✅❌
D-Bus BackdoorCreates a D-Bus service for root reverse shell access.✅❌
Diamorphine RootkitInstalls the Diamorphine Loadable Kernel Module Rootkit.✅❌
Initramfs PersistenceInjects a UID=0 backdoor user into initramfs on reboot.✅❌
Git PersistenceUtilizes Git hooks or pagers to persist within Git repositories.✅✅
Generator PersistenceLeverages systemd generators to create persistent services.✅❌
GRUB BackdoorManipulates GRUB to execute a backdoor at boot.✅❌
Malicious ContainerDeploys a Docker container designed to host escape.✅✅
Malicious PackageInstalls a DPKG/RPM package to achieve persistence.✅❌
NetworkManagerInstalls a dispatcher script to persist upon network actions.✅❌
LD_PRELOAD BackdoorUses LD_PRELOAD to inject malicious libraries for persistence.✅❌
LKM BackdoorLoads a Loadable Kernel Module to maintain persistence.✅❌
MOTD BackdoorAlters Message of the Day (MOTD) to establish persistence.✅❌
Package ManagerManipulates APT/YUM/DNF to establish persistence on usage.✅❌
PAM PersistenceInstalls a PAM backdoor using a rogue module or pam_exec.✅❌
Password ChangeChanges user passwords to secure backdoor accounts.✅❌
Polkit BackdoorCreates an overly permissive Polkit configuration backdoor.✅❌
Reverse ShellEstablishes a reverse shell (supporting multiple LOLBins).✅✅
Shell Profile PersistenceModifies shell profiles to execute scripts upon user login.✅✅
SSH Key PersistenceManipulates SSH keys to maintain persistent access via SSH.✅✅
Sudoers BackdoorAlters the /etc/sudoers file to grant elevated privileges.✅❌
SUID BackdoorBackdoors binaries by setting the SUID bit.✅❌
System Binary BackdoorWraps system binaries to include backdoor functionality.✅❌
Systemd ServiceCreates systemd services that ensure persistence on reboot.✅✅
Udev PersistenceUtilizes drivers to persist at the hardware interaction level.✅❌
Web Shell PersistenceDeploys web servers for remote access via web interfaces.✅✅
XDG AutostartEmploys XDG autostart directories to persist upon user login.✅✅

Support

PANIX offers comprehensive support across various Linux distributions.

DistributionSupportTested Version
Debian✅Debian 11 & 12
Ubuntu✅Ubuntu 22.04 (Diamorphine unavailable)
RHEL✅RHEL 9 (MOTD & Pre-OS Boot techniques unavailable)
CentOS✅CentOS Stream 9 & 7 (MOTD & Pre-OS Boot techniques unavailable)
Fedora✅Not fully tested
Arch Linux✅Not fully tested
OpenSUSE✅Not fully tested
Download Tool