{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/e-d-r/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["persistence","privilege-escalation","linux","e-d-r"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries targeting Linux environments often seek to establish persistence by modifying startup configuration files. This technique involves appending malicious commands, scripts, or binary paths into common shell initialization files such as ~/.bashrc, ~/.bash_profile, or /etc/profile. By successfully modifying these files, an attacker ensures that their arbitrary code executes with the privileges of the user who logs in, or the system account during boot, facilitating long-term access and potential privilege escalation.\u003c/p\u003e\n\u003cp\u003eSecurity operations centers must monitor for processes that perform write operations to these sensitive configuration files, particularly when initiated by utilities like 'echo' or redirect operators. While legitimate system administration tasks may involve these commands, the lack of expected administrative context or unusual patterns of modification can serve as a strong indicator of compromise. This activity is a classic method for maintaining a foothold in a Linux environment and is commonly associated with broader persistence and post-exploitation objectives.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained on the Linux target system (e.g., via web shell or remote exploitation).\u003c/li\u003e\n\u003cli\u003eThe attacker identifies shell profile files (e.g., ~/.bashrc or /etc/profile) to target for persistence.\u003c/li\u003e\n\u003cli\u003eThe attacker utilizes standard utilities like 'echo' or 'printf' to generate malicious command strings.\u003c/li\u003e\n\u003cli\u003eThe attacker uses file redirection operators ('\u0026gt;' or '\u0026gt;\u0026gt;') to append the generated command strings into the target profile file.\u003c/li\u003e\n\u003cli\u003eThe system saves the modified configuration file, embedding the malicious payload into the startup environment.\u003c/li\u003e\n\u003cli\u003eThe attacker waits for a user to initiate a login session or for the system to reboot.\u003c/li\u003e\n\u003cli\u003eThe shell or init process reads the modified profile file and executes the appended malicious command.\u003c/li\u003e\n\u003cli\u003eThe attacker regains execution control on the host, achieving persistent access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful modification of profile files allows attackers to execute arbitrary code with elevated privileges, potentially leading to total system compromise, exfiltration of sensitive data, and further lateral movement within the network. This technique is a high-reward objective for actors aiming for long-term presence on targeted infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM and tune the filter macros to exclude legitimate administrative activity.\u003c/li\u003e\n\u003cli\u003eEnable process-creation logging (e.g., via Sysmon for Linux or auditd) to ensure the full command line is captured for all process executions.\u003c/li\u003e\n\u003cli\u003ePerform regular integrity monitoring on sensitive Linux configuration files, such as ~/.bashrc and /etc/profile, to detect unauthorized modifications.\u003c/li\u003e\n\u003cli\u003eCorrelate process creation events targeting profile files with parent process metadata to identify unauthorized or anomalous parent-child relationships.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T15:46:08Z","date_published":"2026-08-24T15:46:08Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linux-profile-modification/","summary":"This intelligence details the detection of adversaries modifying Linux profile configuration files via command-line utilities to establish persistent code execution upon system login or reboot.","title":"Detection of Malicious Linux Profile Modification for Persistence","url":"https://feed.craftedsignal.io/briefs/2026-08-linux-profile-modification/"}],"language":"en","title":"CraftedSignal Threat Feed - E-D-R","version":"https://jsonfeed.org/version/1.1"}