linux
SSH Persistence
Quick notes on SSH keys, authorized_keys, and detecting persistent SSH access.
2026-09-12
1 min read
linuxsshpersistenceauthenticationenumerationred-team
SSH Key Locations#
Common location:
~/.ssh/authorized_keys
Each line normally contains a public key authorized to access that account.
Useful configuration:
/etc/ssh/sshd_config
/etc/ssh/sshd_config.d/
These files can affect how SSH authentication and access are handled.
ssh enumeration
TTY1ZSH 5.9
Findings
INFO
Suspicious SSH Access
Look for:
• Unknown public keys
• Keys belonging to unexpected users
• Recently modified authorized_keys files
• Suspicious key options
• SSH configuration changes
• Unexpected accounts with SSH access
file inspection
TTY1ZSH 5.9
Takeaway#
SSH keys can provide quiet, long-term access. During a persistence assessment, always check authorized_keys and the SSH configuration of important accounts.
Back to Notesnote: ssh-persistence