LogoClawIndex
CasesSkillsAbout
LogoClawIndex

performing-malware-persistence-investigation - Investigate Malware Persistence Mechanisms

Systematically investigates Windows and Linux persistence mechanisms to identify how malware survives reboots and maintains access.

Tags

Updated: 2026-10-04
forensicsmalware-persistenceautorunsregistryscheduled-tasksrootkit-detectionincident-responsedigital-forensics

Capabilities

Investigate registry persistenceEnumerate scheduled tasksInspect WMI subscriptionsCheck startup folders

Typical Inputs

Forensic imageLive system accessRegistry hives

Typical Outputs

Persistence findingsSuspicious scheduled task recordsregistry_persistence.json

What this skill does

  • Investigate registry persistence
  • Enumerate scheduled tasks
  • Inspect WMI subscriptions
  • Check startup folders
  • Detect DLL hijacking
  • Check COM hijacking

Inputs

  • Forensic image
  • Live system access
  • Registry hives
  • Scheduled task files
  • WMI repository
  • YARA rules
  • Known-good autorun baseline

Outputs

  • Persistence findings
  • Suspicious scheduled task records
  • registry_persistence.json
  • startup_items.txt
  • dll_hijack.txt
  • Console investigation messages

Requirements

  • Administrative privileges
  • Windows or Linux system access
  • Autoruns for Windows
  • RegRipper
  • YARA
  • PyWMIPersistenceFinder
  • Python 3

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.