You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The repository tries to gather an information about Windows persistence mechanisms to make the protection/detection more efficient. Most of the information is well known for years, being actively used within various scenarios.
HKCU Run and RunOnce registry keys - modules/post/windows/manage/persistence_exe.rb
Task Scheduler
Image File Execution Options key
Windows Services
AeDebug
WER Debugger
Natural Language Development Platform 6 DLLs
GPO Client-side Extension
Filter Handlers for Windows Search
Disk Cleanup Handler
.chm helper DLL
hhctrl.ocx
AMSI Providers
ServerLevelPluginDll
Password Filter
Credential Manager DLL
Authentication Packages
Code Signing DLL
HKCU cmd.exe AutoRun
LSA Extension
Winlogon Notification Package
Print Monitor
HKCU Load
MPNotify
Windows Platform Binary Table
Explorer tools
The text was updated successfully, but these errors were encountered:
A thread to track adding persistence techniques from persistence-info project.
The text was updated successfully, but these errors were encountered: