HOWTO: Adding persistence to a live Kali Linux USB drive on a Mac

Most guides tell you how to add persistence via another Linux system. I needed to add persistence from a Mac. Here's what I did...

HOWTO: Adding persistence to a live Kali Linux USB drive on a Mac

After searching for awhile, I assembled the answer from multiple sources. Here it is in one place:

Assuming you have a functioning Live USB, then boot into that. (On a Mac, that means holding down Option on startup.) On Kali’s boot screen, then choose the default top choice to load.

  1. Open up terminal/console and use fdisk -l to make sure you know which is your live USB; it will be something like /dev/sdb
  2. in terminal, type fdisk /dev/sdb (use YOUR correct path here)
  3. in fdisk, now type n for new partition
  4. then select p for primary, and accept the next three defaults for partition number, first sector and last sector
  5. finally, in fdisk, type w to save your changes and exit the program
  6. now back at the main prompt, type reboot now (I do not think this last step is required, but I haven't yet verified.)

You have now created a third partition on your USB with the space not required for Kali. Next up is making that partition encrypted, formatted, and persistent.

  1. Startup that Kali Live USB again and get to the terminal
  2. type cryptsetup -vy luksFormat /dev/sdb3 (again this should be the path to your newly created USB partition). The parameters are v for verbose and y for verify-passphrase.
  3. It will ask ‘are you sure?’ which requires a YES in caps. You will then be prompted for a passphrase. This will be required whenever you first open that partition, so don’t forget it!!
  4. After entering and re-entering your passphrase, cryptsetup will encrypt the partition.
  5. Now open the partition by typing cryptsetup luksOpen /dev/sdb3 my_usb and entering your passphrase
  6. Create the filesystem with mkfs.ext3 -L persistence /dev/mapper/my_usb and expect a bit of time for its creation
  7. When the prompt returns, label the partition with e2label /dev/mapper/my_usb persistence
  1. Now let’s create the mount point and config:
    a. mkdir -p /mnt/my_usb
    b. mount /dev/mapper/my_usb /mnt/my_usb
    c. echo "/ union" > /mnt/my_usb/persistence.conf

  2. Then we’ll unmount the partition and close the encrypted channel:
    a. umount /dev/mapper/my_usb
    b. cryptsetup luksClose /dev/mapper/my_usb

  3. Finally, type reboot now

You are now ready to reboot into Kali Live with Encrypted Persistence!
So select that option at the load screen.
During boot up, you will be prompted to unlock your partition.

HINT: remember that the root password is separate and different from your encryption password.

You are now ready to rock & roll.