Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Ferramentas/GitHubGitHub/raj3shp/persisthunt
Privilege EscalationReconnaissanceContainer SecurityPersistence MechanismsScripting & AutomationForensicsMalware AnalysisDigital ForensicsIncident Response
GitHubraj3shp/persisthunt

persisthunt

Linux Persistence Detection, Hunting and Artifact Collection script

Ver Repositório
25116há 2 mesesRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Linux Persistence Detection, Hunting and Artifact Collection

  • Summary
  • Usage
  • Example Detections
  • Table of Techniques

Summary

persisthunt.sh helps speed up investigations by collecting targeted persistence-related artifacts and highlighting suspicious patterns commonly associated with Linux persistence techniques.

The script assists in persistence detection, threat hunting, and artifact collection across well-known Linux persistence mechanisms. Findings are categorized into three levels - High, Low, and Informational based on confidence and severity. Examples include suspicious autorun entries referencing /tmp/, /home/, /dev/tcp, curl, or detection of active bind/reverse shells.

It is designed as a flexible foundation that defenders can customize for their environments by adding or removing detection logic and keywords. The output can be large and may require environment-specific analysis, but it is also suitable for review and summarization using LLMs or AI agents.

Usage

Run as root user and redirect output to a file

sudo persisthunt.sh > output.log

Run on a remote host via SSH

ssh [email protected] 'bash -s' < persisthunt.sh > output.log 2>&1

Example Detections

=== [HIGH] Active reverse shell ===
bob      3889906  0.0  0.0   2800  1848 pts/2    S+   06:38   0:00 sh -i

=== [HIGH] Active bind shell ===
LISTEN 0      1                                     0.0.0.0:4444  0.0.0.0:* users:(("python3",pid=3891687,fd=3))
bob      3891687  0.7  0.3  19540 12320 pts/3    S+   06:41   0:00 python3 -c exec("""import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind(("0.0.0.0",4444));s1.listen(1);c,a=s1.accept(); while True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())""")

=== [HIGH] eBPF programs with raw network sockets (possible BPFdoor persistence) ===
PID: 3903559, Executable: bpfdoorpoc, Stack trace: /proc/3903559/stack:[<0>] packet_recvmsg+0x6e/0x5c0

=== [LOW] Recent ELF binary in tmp/home/hidden dirs ===
/var/tmp/.test

Techniques

Baixar ferramenta