- What: Webinar on PAMSkeletonKey for Linux PAM abuse
- Impact: IT professionals may need to understand this technique for defense
How does PAM abuse fit into a real‑world attack chain? 🛝 Webcast Slides https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/PAM_Tool_Slide_Deck.pdf Join us for a free one‑hour BHIS webinar with Ben Bowman as he introduces PAMSkeletonKey, a tool designed for red teamers and CTF players to explore persistence, lateral movement, and privilege escalation on Linux systems. Ben will teach why the tool was created, how to use it safely in lab environments, and what this technique means for defenders working to detect or prevent authentication abuse. You'll learn a practical understanding of Linux PAM (Pluggable Authentication Modules) authentication and how it can be abused to create a skeleton‑key backdoor for persistence. Get started with PAMSkeletonKey: https://github.com/her3ticAVI/PAMSkeletonKey Chapters 00:00 - Intro – 2026-04-02 Intro to PAMSkeletonKey for Persistence - Ben Bowman 01:33 - What I Don't Know 02:14 - Remember Mimikatz? Me neither. 03:59 - What is PAM? 04:43 - PAM Architecture Deep Dive 06:54 - PAM Module Types 08:25 - How PAM Authentication Works 12:18 - What does this tell us? 13:44 - What Code Changes Do We Make? 17:28 - Pivoting & Attack Scenarios 18:57 - The Topic of Stolen Valor 21:14 - The Improvements 25:50 - Demo Time 41:57 - References 45:39 - Q&A 59:00 - Antisyphon Training's New LMS Walk Through {{people | title: 'Creators & Guests'}} Chat with your fellow attendees in the BHIS Discord server: https://discord.gg/bhis ( https://discord.gg/bhis ) in the #🔴live-chat channel 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com ( https://poweredbybhis.com/ ) Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.com ( https://www.blackhillsinfosec.com/ ) Antisyphon Traininghttps://www.antisyphontraining.com/ ( https://www.antisyphontraining.com/ ) Active Countermeasureshttps://www.activecountermeasures.com ( https://www.activecountermeasures.com/ ) Wild West Hackin Festhttps://wildwesthackinfest.com ( https://wildwesthackinfest.com/ ) BHIS Webcasts Episode 9 May 13, 2026 ★ Episode details: https://share.transistor.fm/s/9c9af1f5 ★ Additional episodes: https://bhispodcasts-webcasts.transistor.fm