Open Investigator · Linux persistence triage

Triage cron and systemd persistence without giving AI a shell.

Linux persistence alerts often start with a new cron entry, a suspicious systemd unit, an odd shell startup file, or a process that keeps coming back. The first pass should map the persistence clue to evidence before anyone deletes files or restarts services.

Read-only toolsEvidence-backed reportFirst-pass triage
Open Investigator product mark
AI-driven server investigator: incident clues, host evidence, AI follow-up, timeline, and investigation report.

Why it matters

Use this article when a Linux persistence clue needs an evidence-backed first pass before cleanup or containment.

Start from the persistence clue without assuming the host is fully compromised.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.
Correlate cron, systemd, shell startup, process, network, account, and recent-file evidence.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.
Keep deletion, disablement, and service changes outside the AI investigator.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.

Read the source, run the CLI, and send collector or report feedback.