sootmark-persistence-0.4.1
Where Linux and Unix attackers keep access: crontabs, at jobs, systemd units, init scripts, SSH authorized keys and sshd_config, rc.local and shell start-up files, ld.so.preload, sudoers, PAM, udev rules, XDG autostart and kernel modules, read into entries with what runs, as whom and when, and what looks suspicious.
one minute ago