linux
Linux Persistence Fundamentals
Quick notes on common Linux persistence mechanisms and where to look for them.
2026-09-12
2 min read
linuxpersistencered-teamenumeration
Common Persistence Mechanisms#
Cron can execute commands automatically on a schedule.
Common locations:
/etc/crontab
/etc/cron.d/
/etc/cron.hourly/
/etc/cron.daily/
/etc/cron.weekly/
/etc/cron.monthly/
User crontabs can also be used for persistence.
Systemd services and timers can execute programs during boot or at scheduled times.
Useful areas to inspect:
/etc/systemd/system/
/usr/lib/systemd/system/
Pay attention to unusual ExecStart paths.
SSH public keys can provide persistent remote access.
Common location:
~/.ssh/authorized_keys
Unknown keys or unusual key options should be investigated.
Shell startup files can execute commands when a user starts a shell.
Examples:
~/.bashrc
~/.profile
~/.bash_profile
~/.zshrc
/etc/profile
persistence enumeration
TTY1ZSH 5.9
Findings
INFO
Look for:
• Unexpected scheduled jobs
• Unknown systemd services or timers
• Unrecognized SSH keys
• Suspicious commands in shell startup files
• Unusual SUID/SGID binaries
• Unexpected privileged accounts
• Executables running from unusual locations
PersistHunt turns these persistence surfaces into separate detectors and normalizes their observations into standardized findings for analysis and risk scoring.
Back to Notesnote: linux-persistence-fundamentals