
Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH, containers) with confidence scoring and generates CSV/JSONL reports for forensic analysis.
A comprehensive Linux persistence detection tool for Digital Forensics and Incident Response (DFIR) investigations.
Persistnux is a bash-based tool designed to identify known Linux persistence mechanisms used by attackers to maintain access to compromised systems. It performs comprehensive checks across the system and generates detailed reports in both CSV and JSONL formats for further analysis.
.service) in /etc/systemd/system, /lib/systemd/system, /usr/lib/systemd/system/etc/crontab, /etc/cron.d/*)/etc/cron.{daily,hourly,weekly,monthly})/etc/cron.allow and /etc/cron.deny ACL files — entries referencing nonexistent users flagged/etc/profile, /etc/bash.bashrc, /etc/zshrc)/etc/profile.d/*).bashrc, .bash_profile, .zshrc, .profile, etc.)/etc/rc.local and variants/etc/init.d)/etc/rc*.d)/etc/ld.so.preload) — each listed library verified via package manager/etc/ld.so.conf, /etc/ld.so.conf.d/) — conf file integrity + non-standard path .so files scanned and verified/etc/environment LD_PRELOAD/LD_LIBRARY_PATH — env file flagged HIGH; referenced library paths verified (unmanaged/modified → CRITICAL)/etc/modprobe.d/, /etc/modprobe.conf) — file integrity; install directives analyzed for suspicious command targets; blacklist of security modules (apparmor, selinux, seccomp) flagged HIGH/etc/modules, /etc/modules-load.d/) — config integrity; referenced module names resolved to .ko files via modinfo and verifiedlsmod) — enumeration and integrity verification.config/autostart, /etc/xdg/autostart) — all user homes scanned when root/etc/environment) — LD_PRELOAD/LD_LIBRARY_PATH library paths verified/etc/sudoers, /etc/sudoers.d/) — NOPASSWD/ALL patterns → HIGH.so modules verified via package manager; @include directives followed; /etc/pam.conf includedpam_exec.so script analysis — missing/suspicious scripts → CRITICALpam_python.so / pam_perl.so relay detection — script extracted and analyzedpam_script.so hook file detection in /etc/security/pam_env.conf and ~/.pam_environment LD_PRELOAD library verification/etc/security/ general scan/etc/update-motd.d/) — package verification; modified → CRITICAL~/.ssh/authorized_keys — recently modified keys flagged; command= option content analyzed for suspicious patterns~/.ssh/rc — presence flagged MEDIUM; suspicious/reverse shell content → HIGH/CRITICALdpkg -V on Debian/Ubuntu, rpm -Va on RHEL/CentOS)/usr/bin, /usr/sbin, /bin, /sbin → CRITICAL finding/lib/security → CRITICAL findinginit= kernel parameter injection (/etc/default/grub, /etc/default/grub.d/*.cfg)/pre-pivot hooks writing to /sysroot/etc/shadow/etc/initramfs-tools/scripts/ and /hooks//boot/initrd.img-* images (mtime-based).pkla files with unconditional ResultAny/ResultInactive/ResultActive=yesunix-user:*) grants.rules files with unconditional polkit.Result.YES (JavaScript-based Polkit >= 0.106)Exec= registration (/usr/share/dbus-1/system-services/)allow own="*" or send_destination="*" directives/etc/NetworkManager/dispatcher.d/)RUN+= directives executing arbitrary commands or scripts (/etc/udev/rules.d/, /lib/udev/rules.d/)/run/udev/rules.d/at/cron delegation patterns in RUN+= (common foreground restriction bypass)--privileged, --pid=host)docker.sock bind-mounts into containers (full host control via Docker API)nsenter -t 1 in container entrypoints or Dockerfilesgetcap — cap_setuid+ep on GTFOBins → CRITICAL.original, .old, .bak, .real) with wrapper scripts/etc/passwd/etc/passwd shell fieldauthorized_keys files# Clone the repository
git clone https://github.com/yourusername/persistnux.git
cd persistnux
# Make the script executable
chmod +x persistnux.sh
# Run with default settings (shows only suspicious findings)
sudo ./persistnux.sh
# Show help and all options
./persistnux.sh --help
# Run as regular user (limited scope)
./persistnux.sh
By default, Persistnux shows only suspicious findings (MEDIUM, HIGH, CRITICAL confidence) to reduce noise and focus on actionable threats.
# Default: Show only suspicious findings
sudo ./persistnux.sh
# Show all findings including baseline (LOW confidence)
sudo ./persistnux.sh --all
# OR
sudo FILTER_MODE=all ./persistnux.sh
# Show only HIGH and CRITICAL confidence findings
sudo MIN_CONFIDENCE=HIGH ./persistnux.sh
# Combine filters: HIGH confidence only
sudo ./persistnux.sh --min-confidence HIGH