sootmark-persistence 0.2.0
Where Linux and Unix attackers keep access: crontabs, at jobs, systemd units, init scripts, SSH authorized keys and sshd_config, rc.local and shell start-up files, ld.so.preload, sudoers and PAM, read into entries with what runs, as whom and when, and what looks suspicious.