Intro to PAMSkeletonKey for Persistence w/ Ben Bowman
How does PAM abuse fit into a real‑world attack chain?
🛝 Webcast Slides
https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/PAM_Tool_Slide_Deck.pdf
Join us for a free one‑hour BHIS webinar with Ben Bowman as he introduces PAMSkeletonKey, a tool designed for red teamers and CTF players to explore persistence, lateral movement, and privilege escalation on Linux systems.
Ben will teach why the tool was created, how to use it safely in lab environments, and what this technique means for defenders working to detect or prevent authentication abuse.
You'll learn a practical understanding of Linux PAM (Pluggable Authentication Modules) authentication and how it can be abused to create a skeleton‑key backdoor for persistence.
Get started with PAMSkeletonKey: https://github.com/her3ticAVI/PAMSkeletonKey
Chapters
Chat with your fellow attendees in the BHIS Discord server:
https://discord.gg/bhis
in the #🔴live-chat channel
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com
Brought to you by:
🛝 Webcast Slides
https://www.blackhillsinfosec.com/wp-content/uploads/2026/04/PAM_Tool_Slide_Deck.pdf
Join us for a free one‑hour BHIS webinar with Ben Bowman as he introduces PAMSkeletonKey, a tool designed for red teamers and CTF players to explore persistence, lateral movement, and privilege escalation on Linux systems.
Ben will teach why the tool was created, how to use it safely in lab environments, and what this technique means for defenders working to detect or prevent authentication abuse.
You'll learn a practical understanding of Linux PAM (Pluggable Authentication Modules) authentication and how it can be abused to create a skeleton‑key backdoor for persistence.
Get started with PAMSkeletonKey: https://github.com/her3ticAVI/PAMSkeletonKey
Chapters
- (00:00) - Intro – 2026-04-02 Intro to PAMSkeletonKey for Persistence - Ben Bowman
- (01:33) - What I Don't Know
- (02:14) - Remember Mimikatz? Me neither.
- (03:59) - What is PAM?
- (04:43) - PAM Architecture Deep Dive
- (06:54) - PAM Module Types
- (08:25) - How PAM Authentication Works
- (12:18) - What does this tell us?
- (13:44) - What Code Changes Do We Make?
- (17:28) - Pivoting & Attack Scenarios
- (18:57) - The Topic of Stolen Valor
- (21:14) - The Improvements
- (25:50) - Demo Time
- (41:57) - References
- (45:39) - Q&A
- (59:00) - Antisyphon Training's New LMS Walk Through
Chat with your fellow attendees in the BHIS Discord server:
https://discord.gg/bhis
in the #🔴live-chat channel
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com
Brought to you by:
Black Hills Information Security
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Creators and Guests
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Guest
Ben Bowman
Ben Bowman is a BHIS Security Consultant who joined in 2023, bringing research experience from Madison Cyber Labs and a longtime passion for the company, and who enjoys learning from his team while spending his free time fishing, swimming, and spelunking.
Guest
Brett Jones
Brett Jones joined Black Hills Information Security (BHIS) in February 2025 as a Security Consultant. In this role, he performs penetration testing, working with companies to ensure their networks are secure. Previously, Brett was in the Army for 11 years conducting Offensive Cyber Operations. He came to BHIS through SkillBridge, a program that connects service members with real-world training and work experience in high-demand fields before their military discharge. Brett was drawn to BHIS through the sense of fellowship and camaraderie exhibited by BHIS employees and the online BHIS community. He is actively involved within the community, regularly joining Antisyphon Ask Me Anythings (AMA’s) and sharing his knowledge and experience with others to help everyone grow and succeed. Outside work, Brett enjoys reading books, playing video games, and working on his personal fitness.
Guest
Logan Bender
Logan Bender joined Black Hills Information Security (BHIS) as a Business Consultant in September 2021. Previously working as a technology advisor, Logan now advises clients on BHIS’s services and provides recommendations for improving security posture. He is excited to be part of an organization that is so involved in providing quality security content to the community, and he loves the team and helpful culture at BHIS. When he’s not working, Logan can be found in the great outdoors — camping, fishing, hunting, golfing, or snowboarding.
Producer
Ryan Poirier
Ryan Poirier began his time at Black Hills Information Security (BHIS) as the Video Producer and Editor in August 2020. Ryan polishes and perfects every webcast, podcast, and workshop on the BHIS, ACM, and WWHF YouTube Channels. Prior to Ryan’s time at BHIS, he worked for one of the largest public schools in the United States, conducting their video production and live broadcasting. He joined the BHIS team because he felt like it would be a great group of people to work with, and he couldn’t pass up the perfect next step in his career. Outside of his time with BHIS, Ryan does freelance photography, attends Cars & Coffee events, and expands his knowledge of audio and videos.