For SOC and IR teams operating in Linux environments: persistence mechanisms (cron/systemd/shell startup files/SSH authorized_keys/LD_PRELOAD/kernel module), privilege escalation paths (SUID/SGID, sudo misconfiguration, capabilities), and the forensic analysis methodology that surfaces them — auditd ruleset, auth.log/journald queries, /proc live response, and hardening controls.
Technique Library
MITRE ATT&CK-based attack techniques — Exploit · Prevention · Detection
38 techniques
T1543.002PersistenceAdvanced
19 min read
Exploit
Prevention
Detection
T1574.001PersistenceAdvanced
A comprehensive map of how attackers abuse Windows DLL loading mechanisms: DLL search order hijacking (T1574.001), side-loading (T1574.002), phantom DLL, COM hijacking (T1546.015, InprocServer32/HKCU), AppInit_DLLs (T1546.010), AppCert DLLs (T1546.009), Netsh helper DLL (T1546.007), and Application Shimming (T1546.011). KnownDLLs and WinSxS protection mechanisms, Sysmon EID 7 (ImageLoad)-based detection, and SafeDllSearchMode hardening guide.
16 min read
Exploit
Prevention
Detection
3 / 3Next →