网络安全 Analyzing Persistence Mechanisms In Linux

Model: minimax-m3 | ¥0.20/call
网络安全Claude Opus 4.7安全审计AnalyzingMechanisms

Analyzing Persistence Mechanisms In Linux:网络安全 skill: analyzing-persistence-mechanisms-in-li,适用于安全分析、取证与威胁排查场景。

Calls: 1

Skill Documentation

网络安全 Analyzing Persistence Mechanisms In Linux

摘要

Analyzing Persistence Mechanisms In Linux:网络安全 skill: analyzing-persistence-mechanisms-in-li,适用于安全分析、取证与威胁排查场景。

> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集

> 原文件: skills/analyzing-persistence-mechanisms-in-linux/SKILL.md

> 模型推荐: claude-opus-4-7 (安全分析深度推理)

这个 skill 是干嘛的

mukul975 整理的 100+ 个网络安全专业 skill — 覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。

michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。

---

🤖 Agent 使用说明

1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时触发对应 skill

2. skill 按操作步骤执行(取证镜像 / 解析日志 / 跑威胁情报)

3. 涉及破坏性操作前必须 ask user 确认

4. 完工后跑自检

5. 区分"防御性分析" vs "恶意代码审计"

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 按 Agent 提示提供文件/镜像/日志/哈希

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

原 skill 内容(mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-persistence-mechanisms-in-linux/SKILL.md,截断到 12k chars)

---

name: analyzing-persistence-mechanisms-in-linux

description: Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.

domain: cybersecurity

subdomain: threat-hunting

tags:

mitre_attack:

version: '1.0'

author: mahipal

license: Apache-2.0

d3fend_techniques:

nist_csf:

---

Analyzing Persistence Mechanisms in Linux

Overview

Adversaries establish persistence on Linux systems through crontab jobs, systemd service/timer units, LD_PRELOAD library injection, shell profile modifications (.bashrc, .profile), SSH authorized_keys backdoors, and init script manipulation. This skill scans for all known persistence vectors, checks file timestamps and integrity, and correlates findings with auditd logs to build a timeline of persistence installation.

When to Use

Prerequisites

Steps

1. **Scan Crontab Entries** — Enumerate all user crontabs, /etc/cron.d/, /etc/cron.daily/, and anacron jobs for suspicious commands

2. **Audit Systemd Units** — Check /etc/systemd/system/ and ~/.config/systemd/user/ for non-package-managed service and timer units

3. **Detect LD_PRELOAD Hijacking** — Check /etc/ld.so.preload and LD_PRELOAD environment variable for injected shared libraries

4. **Inspect Shell Profiles** — Scan .bashrc, .bash_profile, .profile, /etc/profile.d/ for injected commands or reverse shells

5. **Check SSH Authorized Keys** — Audit all authorized_keys files for unauthorized public keys with command restrictions

6. **Correlate Auditd Logs** — Search auditd logs for file modification events on persistence paths to build an installation timeline

7. **Generate Persistence Report** — Produce a risk-scored report of all discovered persistence mechanisms

Expected Output

常见问题(FAQ)

使用「Analyzing Pers」这个 skill 能解决什么问题?

本 skill 专注于Analyzing Pers,网络安全 skill: analyzing-persistence-mechanisms-in-linux。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Analyzing Pers」?

当你需要在Analyzing Persistence Mechanisms In Linux相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Analyzing Pers」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。

FAQ

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 按 Agent 提示提供文件/镜像/日志/哈希

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

使用「Analyzing Pers」这个 skill 能解决什么问题?

本 skill 专注于Analyzing Pers,网络安全 skill: analyzing-persistence-mechanisms-in-linux。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Analyzing Pers」?

当你需要在Analyzing Persistence Mechanisms In Linux相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Analyzing Pers」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。