linux-persistence: Demonstrate Linux Persistence Techniques

Summary
A Go project presenting Linux persistence and covert-access techniques for security research and authorized testing. Its README describes a broad set of mechanisms, including scheduled tasks, authentication changes, and network-based access.
At a glance
- Language
- Go
- Stars
- 35
- Forks
- 6
- Added to OSRepos
- October 11, 2025
- Last analyzed
- October 3, 2026
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
linux-persistence is a Go-based security research project that demonstrates multiple ways persistence and covert access can be established on Linux systems. It is intended for authorized testing and education, rather than routine system administration.
The project may help security teams understand persistence risks and plan detection exercises in controlled environments. Its README describes potentially harmful capabilities, including credential capture and backdoor access, so use should be limited to isolated systems with explicit authorization.
Key Features
- Describes reverse-shell and network-listener mechanisms.
- Covers persistence through scheduled tasks and hidden files.
- Includes examples involving PAM, setuid binaries, and kernel modules.
- Describes ICMP, DNS, and port-reuse communication methods.
- Includes detection suggestions involving processes, network connections, scheduled tasks, and kernel modules.
Use Cases
- Security educators can use the project as a discussion aid for Linux persistence risks.
- Authorized red teams can assess whether monitoring detects persistence mechanisms in a controlled environment.
- Blue teams can use the README's technique categories to inform detection reviews and incident-response exercises.
- Security researchers can examine the project as a catalog of potentially harmful techniques without deploying it on systems they do not own or have permission to test.
Project Facts
- Language: Go
- Stars: 35
- Forks: 6
- Archived: No
Getting Started
Review the repository README before considering any testing. It describes the project’s requirements and usage; only evaluate it in an isolated environment where you have explicit authorization.
Considerations
- The README describes backdoors, covert access, and credential-capture behavior. Running such code can compromise systems and expose sensitive information.
- The README lists dependencies including GCC, Linux kernel development headers, PAM development libraries, and iptables. Some techniques require elevated privileges or system-level changes.
- The repository was created and last pushed on 2025-08-19, and the input reports one open issue. These facts do not establish how complete or reliable the implementation is.
- No license is specified in the provided repository data. The README’s educational-use notice is not a formal license grant.
Source repository
Open the original repository on GitHub.
21 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

e2a: Open-Source Email API for Applications and AI Agents
September 29, 2026
e2a is an open-source email API designed for applications and AI agents, offering robust transactional email capabilities and real two-way inboxes. It supports both managed hosting and self-hosting with Docker, providing features like human-in-the-loop approval and advanced content screening. Built in Go, e2a aims to bridge email's universal addressability with the structured data world of AI agents.

Router: Optimize AI Model Selection and Costs for Agentic Systems
September 28, 2026
The Weave-OS Router is an intelligent model router for agentic systems, optimizing AI model selection for every request. It acts as a drop-in proxy for major AI providers, routing prompts to the most suitable model in under 50ms. This solution helps users significantly cut costs, often by 40-70%, simply by changing an endpoint.

KSail: The All-in-One Kubernetes SDK for Cluster Management and GitOps
September 27, 2026
KSail is a comprehensive Kubernetes SDK designed to simplify cluster creation, management, and operation across multiple distributions like Kind, K3d, Talos, and VCluster. It integrates essential features such as GitOps, secrets management, an AI assistant, and an MCP server, making cloud-native development accessible with just Docker or a cloud provider.

Memoh: Give AI Agents Dedicated Cloud Computers
September 26, 2026
Memoh is a multi-agent platform that gives each agent an isolated, always-on workspace with a desktop, browser, network access, and long-term memory. Use your own API keys or host agents such as Claude Code and Codex, either in Memoh Cloud or on your own infrastructure.