Analyzing Persistence Mechanisms in Linux
SkillMonitoring & opsAnalyzing-persistence-mechanisms-in-linux is an agent skill for threat hunting and incident response. It guides the agent through scanning a Linux host for persistence mechanisms such as crontab entries, systemd units, LD_PRELOAD injection, shell profile modifications, and SSH authorized_keys backdoors, then correlates findings with auditd logs into an installation timeline.
Use Analyzing Persistence Mechanisms in Linux in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Analyzing Persistence Mechanisms in Linux and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Analyzing Persistence Mechanisms in Linux skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have root or sudo access on the target Linux system or a forensic image.
What your AI can do with it
- Enumerate user crontabs, /etc/cron.d/, /etc/cron.daily/, and anacron jobs for suspicious
- Check /etc/systemd/system/ and ~/.config/systemd/user/ for non-package-managed service
- Detect LD_PRELOAD hijacking via /etc/ld.so.preload and the LD_PRELOAD environment
- Scan .bashrc, .bash_profile, .profile, and /etc/profile.d/ for injected commands
- Audit authorized_keys files for unauthorized public keys with command restrictions
- Correlate auditd logs into an installation timeline and output a risk-scored JSON report
Getting started
- Have root or sudo access on the target Linux system or a forensic image.
- Configure auditd with file watch rules on persistence paths.
- Have Python 3.8 or later with the standard library (os, subprocess, json) available.
- Optionally, run an OSSEC/Wazuh agent for file integrity monitoring alerts.
- Add the skill to your agent and ask it to scan the host for persistence mechanisms.
What this skill tells your AI
The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/analyzing-persistence-mechanisms-in-linux/SKILL.md and read by ahel’s review.
Overview
Adversaries establish persistence on Linux systems through crontab jobs, systemd service/timer units, LD_PRELOAD library injection, shell profile modifications (.bashrc, .profile), SSH authorized_keys backdoors, and init script manipulation. This skill scans for all known persistence vectors, checks file timestamps and integrity, and correlates findings with auditd logs to build a timeline of persistence installation.
When to Use
- When investigating security incidents that require analyzing persistence mechanisms in linux
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
Prerequisites
- Root or sudo access on target Linux system (or forensic image)
- auditd configured with file watch rules on persistence paths
- Python 3.8+ with standard library (os, subprocess, json)
- Optional: OSSEC/Wazuh agent for file integrity monitoring alerts
Steps
- Scan Crontab Entries — Enumerate all user crontabs, /etc/cron.d/, /etc/cron.daily/, and anacron jobs for suspicious commands
- Audit Systemd Units — Check /etc/systemd/system/ and ~/.config/systemd/user/ for non-package-managed service and timer units
- Detect LD_PRELOAD Hijacking — Check /etc/ld.so.preload and LD_PRELOAD environment variable for injected shared libraries
- Inspect Shell Profiles — Scan .bashrc, .bash_profile, .profile, /etc/profile.d/ for injected commands or reverse shells
- Check SSH Authorized Keys — Audit all authorized_keys files for unauthorized public keys with command restrictions
- Correlate Auditd Logs — Search auditd logs for file modification events on persistence paths to build an installation timeline
- Generate Persistence Report — Produce a risk-scored report of all discovered persistence mechanisms
Expected Output
- JSON report of all persistence mechanisms found with risk scores
- Timeline of persistence installation from auditd correlation
- MITRE ATT&CK technique mapping (T1053, T1543, T1574, T1546)
- Remediation commands for each detected persistence mechanism
Signals
- GitHub stars
- 34k
- Forks
- 4k
- Last commit
- Aug 2026
Questions
- What persistence mechanisms does it check?
- Crontab jobs, systemd service and timer units, LD_PRELOAD library injection, shell profile modifications (.bashrc, .profile), SSH authorized_keys backdoors, and init script manipulation.
- What does the report contain?
- A risk-scored JSON report of all discovered persistence mechanisms, with MITRE ATT&CK mappings and remediation commands.
Advanced
- Item type
- skill
- Key
analyzing-persistence-mechanisms-in-linux-mukul975- Source
- github.com/mukul975/anthropic-cybersecurity-skills
github.com/mukul975/anthropic-cybersecurity-skills
Related picks
Skill · wshobson
The pick for Pythonpython-pro
Skill · jeffallan
The pick for Pythongenerate-sandbox-policy
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infrasecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secrets