( 03 )NOTES/SSH_PERSISTENCE
SYNC0x4A1F
notes/ssh-persistence
linux

SSH Persistence

Quick notes on SSH keys, authorized_keys, and detecting persistent SSH access.

2026-09-12
1 min read
linuxsshpersistenceauthenticationenumerationred-team

SSH Key Locations#

Common location: ~/.ssh/authorized_keys Each line normally contains a public key authorized to access that account.
Useful configuration: /etc/ssh/sshd_config /etc/ssh/sshd_config.d/ These files can affect how SSH authentication and access are handled.
ssh enumeration
>ls -la ~/.ssh/
>cat ~/.ssh/authorized_keys
>sudo grep -v '^#' /etc/ssh/sshd_config
>
Findings
INFO
Suspicious SSH Access Look for: • Unknown public keys • Keys belonging to unexpected users • Recently modified authorized_keys files • Suspicious key options • SSH configuration changes • Unexpected accounts with SSH access
file inspection
>stat ~/.ssh/authorized_keys
>ls -l ~/.ssh/authorized_keys
>

Takeaway#

SSH keys can provide quiet, long-term access. During a persistence assessment, always check authorized_keys and the SSH configuration of important accounts.

Back to Notesnote: ssh-persistence