2026-09-25 –, Off-Main Track
Standard Linux persistence tracking typically focuses heavily on the more obvious artefacts like cron jobs, rc.local scripts, and standard systemd services. Because security teams look there first, modern attackers are shifting to more elegant, hook-based execution vectors that bypass traditional file-integrity monitoring.
This talk dives into dissecting two low-overhead Linux persistence mechanisms: dynamic linker hijacking and Systemd Generators. We will look at the underlying OS mechanics of both vectors, look at a live example of how easily it can blend into legitimate infrastructure and how you can audit them across your entire fleet tomorrow.
Jason has spent over six years working as a digital forensics and incident response analyst, investigating critical incidents across nearly every industry sector. Dealing with ransomware and business email compromise on a daily basis, he is intimately familiar with the realities of modern incident triage. Jason spends his spare time researching cloud security and writing custom tools and programs to streamline complex forensic investigations.