Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Persistnux — Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH, containers) with confidence scoring and generates CSV/JSONL reports for forensic analysis. | Kitploit
Tools/GitHubGitHub/go-lanz/persistnux
Privilege EscalationPersistence MechanismsVulnerability AnalysisForensicsMalware AnalysisDigital ForensicsLearning & EducationIncident ResponseContainer EscapeLabs & Practice
GitHubgo-lanz/persistnux
3182 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Persistnux

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH, containers) with confidence scoring and generates CSV/JSONL reports for forensic analysis.

View Repository

Persistnux

A comprehensive Linux persistence detection tool for Digital Forensics and Incident Response (DFIR) investigations.

Overview

Persistnux is a bash-based tool designed to identify known Linux persistence mechanisms used by attackers to maintain access to compromised systems. It performs comprehensive checks across the system and generates detailed reports in both CSV and JSONL formats for further analysis.

Features

  • Comprehensive Detection: Covers all major Linux persistence mechanisms
  • Live Analysis: Runs directly on live systems with minimal dependencies
  • Detailed Output: Generates CSV and JSONL reports with file hashes, metadata, and confidence scores
  • Root and Non-Root: Works with or without root privileges (with limited scope for non-root)
  • DFIR-Ready: Output formats compatible with common DFIR tools and workflows
  • Suspicion Scoring: Automatic confidence scoring (LOW, MEDIUM, HIGH, CRITICAL) based on indicators
  • False Positive Reduction: Package manager integration and known-good service whitelisting
  • Time-Based Analysis: Recently modified files receive higher confidence scores
  • Pattern Matching: Detects reverse shells, download-execute patterns, obfuscation techniques

Persistence Mechanisms Detected

1. Systemd Services

  • Service files (.service) in /etc/systemd/system, /lib/systemd/system, /usr/lib/systemd/system
  • User-level systemd services
  • Filters out disabled services and services without ExecStart
  • Detects suspicious ExecStart commands
  • Verifies package integrity of executed binaries/scripts

2. Cron Jobs & Scheduled Tasks

  • System crontabs (/etc/crontab, /etc/cron.d/*)
  • Periodic execution directories (/etc/cron.{daily,hourly,weekly,monthly})
  • User crontabs for all users (root mode)
  • At jobs
  • Suspicious command patterns in scheduled tasks
  • /etc/cron.allow and /etc/cron.deny ACL files — entries referencing nonexistent users flagged

3. Shell Profiles & RC Files

  • System-wide profiles (/etc/profile, /etc/bash.bashrc, /etc/zshrc)
  • Profile.d scripts (/etc/profile.d/*)
  • User profiles (.bashrc, .bash_profile, .zshrc, .profile, etc.)
  • Fish shell configurations
  • Detects malicious commands in profile files

4. Init Scripts & RC.local

  • /etc/rc.local and variants
  • SysV init scripts (/etc/init.d)
  • Runlevel scripts (/etc/rc*.d)
  • Detects suspicious download/execution commands

5. Kernel Modules & Library Preloading

  • LD_PRELOAD configurations (/etc/ld.so.preload) — each listed library verified via package manager
  • Dynamic linker configurations (/etc/ld.so.conf, /etc/ld.so.conf.d/) — conf file integrity + non-standard path .so files scanned and verified
  • /etc/environment LD_PRELOAD/LD_LIBRARY_PATH — env file flagged HIGH; referenced library paths verified (unmanaged/modified → CRITICAL)
  • Kernel module parameters (/etc/modprobe.d/, /etc/modprobe.conf) — file integrity; install directives analyzed for suspicious command targets; blacklist of security modules (apparmor, selinux, seccomp) flagged HIGH
  • Kernel module auto-load configs (/etc/modules, /etc/modules-load.d/) — config integrity; referenced module names resolved to .ko files via modinfo and verified
  • Loaded kernel modules (lsmod) — enumeration and integrity verification

6. Additional Mechanisms

  • XDG autostart entries (.config/autostart, /etc/xdg/autostart) — all user homes scanned when root
  • System environment files (/etc/environment) — LD_PRELOAD/LD_LIBRARY_PATH library paths verified
  • Sudoers configurations and drop-ins (/etc/sudoers, /etc/sudoers.d/) — NOPASSWD/ALL patterns → HIGH
  • PAM (Pluggable Authentication Modules):
    • All .so modules verified via package manager; @include directives followed; /etc/pam.conf included
    • pam_exec.so script analysis — missing/suspicious scripts → CRITICAL
    • pam_python.so / pam_perl.so relay detection — script extracted and analyzed
    • pam_script.so hook file detection in /etc/security/
    • Config file integrity — modified package-owned PAM configs → CRITICAL
    • pam_env.conf and ~/.pam_environment LD_PRELOAD library verification
    • /etc/security/ general scan
  • MOTD scripts (/etc/update-motd.d/) — package verification; modified → CRITICAL
  • Git credential helpers and core.pager settings — content analysis for all users
  • Web shells in common web directories

8. SSH Persistence

  • Per-user ~/.ssh/authorized_keys — recently modified keys flagged; command= option content analyzed for suspicious patterns
  • Per-user ~/.ssh/rc — presence flagged MEDIUM; suspicious/reverse shell content → HIGH/CRITICAL

9. Binary Hijacking

  • Verifies installed system binaries against the package database (dpkg -V on Debian/Ubuntu, rpm -Va on RHEL/CentOS)
  • Modified files in /usr/bin, /usr/sbin, /bin, /sbin → CRITICAL finding
  • Modified PAM modules in /lib/security → CRITICAL finding
  • Conffiles (dpkg configuration files) are excluded to avoid false positives

10. Bootloader & Initramfs

  • GRUB init= kernel parameter injection (/etc/default/grub, /etc/default/grub.d/*.cfg)
  • Root-level dropped init scripts at /
  • Dracut initramfs modules with pre-pivot hooks writing to /sysroot/etc/shadow
  • Ubuntu initramfs-tools hook scripts in /etc/initramfs-tools/scripts/ and /hooks/
  • Recently modified /boot/initrd.img-* images (mtime-based)

11. Polkit (PolicyKit) Manipulation

  • .pkla files with unconditional ResultAny/ResultInactive/ResultActive=yes
  • Wildcard identity (unix-user:*) grants
  • .rules files with unconditional polkit.Result.YES (JavaScript-based Polkit >= 0.106)

12. D-Bus & NetworkManager

  • Malicious D-Bus system service Exec= registration (/usr/share/dbus-1/system-services/)
  • D-Bus policy wildcard allow own="*" or send_destination="*" directives
  • NetworkManager dispatcher scripts (/etc/NetworkManager/dispatcher.d/)

13. Udev Rules

  • Udev RUN+= directives executing arbitrary commands or scripts (/etc/udev/rules.d/, /lib/udev/rules.d/)
  • Runtime-injected rules in /run/udev/rules.d/
  • at/cron delegation patterns in RUN+= (common foreground restriction bypass)

14. Container Escape

  • Privileged Docker containers (--privileged, --pid=host)
  • docker.sock bind-mounts into containers (full host control via Docker API)
  • nsenter -t 1 in container entrypoints or Dockerfiles
  • Dockerfiles in user-writable directories containing escape techniques

15. Advanced Binary & Privilege Checks

  • Active SUID/SGID filesystem scan across system directories
  • File capability scan via getcap — cap_setuid+ep on GTFOBins → CRITICAL
  • Binary hijacking: renamed originals (.original, .old, .bak, .real) with wrapper scripts
  • Non-root accounts with UID 0 in /etc/passwd
  • Shell masking via trailing space in /etc/passwd shell field
  • System accounts (UID 1-999) with SSH authorized_keys files

Installation

# Clone the repository
git clone https://github.com/yourusername/persistnux.git
cd persistnux

# Make the script executable
chmod +x persistnux.sh

Usage

Basic Usage (Live Analysis)

# Run with default settings (shows only suspicious findings)
sudo ./persistnux.sh

# Show help and all options
./persistnux.sh --help

# Run as regular user (limited scope)
./persistnux.sh

Filtering Options (v2.4+)

By default, Persistnux shows only suspicious findings (MEDIUM, HIGH, CRITICAL confidence) to reduce noise and focus on actionable threats.

# Default: Show only suspicious findings
sudo ./persistnux.sh

# Show all findings including baseline (LOW confidence)
sudo ./persistnux.sh --all
# OR
sudo FILTER_MODE=all ./persistnux.sh

# Show only HIGH and CRITICAL confidence findings
sudo MIN_CONFIDENCE=HIGH ./persistnux.sh

# Combine filters: HIGH confidence only
sudo ./persistnux.sh --min-confidence HIGH
Download Tool