
Linux Persistence Detection, Hunting and Artifact Collection script
persisthunt.sh helps speed up investigations by collecting targeted persistence-related artifacts and highlighting suspicious patterns commonly associated with Linux persistence techniques.
The script assists in persistence detection, threat hunting, and artifact collection across well-known Linux persistence mechanisms. Findings are categorized into three levels - High, Low, and Informational based on confidence and severity. Examples include suspicious autorun entries referencing /tmp/, /home/, /dev/tcp, curl, or detection of active bind/reverse shells.
It is designed as a flexible foundation that defenders can customize for their environments by adding or removing detection logic and keywords. The output can be large and may require environment-specific analysis, but it is also suitable for review and summarization using LLMs or AI agents.
Run as root user and redirect output to a file
sudo persisthunt.sh > output.log
Run on a remote host via SSH
ssh [email protected] 'bash -s' < persisthunt.sh > output.log 2>&1
=== [HIGH] Active reverse shell ===
bob 3889906 0.0 0.0 2800 1848 pts/2 S+ 06:38 0:00 sh -i
=== [HIGH] Active bind shell ===
LISTEN 0 1 0.0.0.0:4444 0.0.0.0:* users:(("python3",pid=3891687,fd=3))
bob 3891687 0.7 0.3 19540 12320 pts/3 S+ 06:41 0:00 python3 -c exec("""import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind(("0.0.0.0",4444));s1.listen(1);c,a=s1.accept(); while True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())""")
=== [HIGH] eBPF programs with raw network sockets (possible BPFdoor persistence) ===
PID: 3903559, Executable: bpfdoorpoc, Stack trace: /proc/3903559/stack:[<0>] packet_recvmsg+0x6e/0x5c0
=== [LOW] Recent ELF binary in tmp/home/hidden dirs ===
/var/tmp/.test