performing-malware-persistence-investigation - Investigate Malware Persistence Mechanisms
Systematically investigates Windows and Linux persistence mechanisms to identify how malware survives reboots and maintains access.
Tags
Updated: 2026-10-04forensicsmalware-persistenceautorunsregistryscheduled-tasksrootkit-detectionincident-responsedigital-forensics
Capabilities
Typical Inputs
What this skill does
- Investigate registry persistence
- Enumerate scheduled tasks
- Inspect WMI subscriptions
- Check startup folders
- Detect DLL hijacking
- Check COM hijacking
Inputs
- Forensic image
- Live system access
- Registry hives
- Scheduled task files
- WMI repository
- YARA rules
- Known-good autorun baseline
Outputs
- Persistence findings
- Suspicious scheduled task records
- registry_persistence.json
- startup_items.txt
- dll_hijack.txt
- Console investigation messages
Requirements
- Administrative privileges
- Windows or Linux system access
- Autoruns for Windows
- RegRipper
- YARA
- PyWMIPersistenceFinder
- Python 3
