LogoClawIndex
CasesSkillsAbout
LogoClawIndex

performing-malware-persistence-investigation - Investigate malware persistence across Windows and Linux

Systematically investigates Windows and Linux persistence mechanisms to identify how malware survives reboots and maintains access.

Tags

Updated: 2026-10-04

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Enumerate registry persistence
  • Analyze scheduled task XML
  • Inspect WMI event subscriptions
  • Check startup folder contents
  • Detect DLL search hijacking
  • Inspect COM object hijacking
  • Scan persistence locations
  • Compare autorun entries
  • Verify persistence removal

Inputs

  • Forensic image
  • Live system access
  • Known-good autorun baseline
  • YARA rules

Outputs

  • registry_persistence.json
  • startup_items.txt
  • dll_hijack.txt
  • Copied scheduled task files
  • Copied WMI repository files
  • Persistence findings

Requirements

  • Administrative privileges
  • Windows and Linux persistence knowledge
  • Sysinternals Autoruns
  • RegRipper
  • Python Registry library
  • YARA scanning support
  • PyWMIPersistenceFinder

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
digital forensics
malware persistence
autoruns
Windows registry
scheduled tasks
rootkit detection
incident response
Enumerate registry persistence
Analyze scheduled task XML
Inspect WMI event subscriptions
Check startup folder contents
Forensic image
Live system access
Known-good autorun baseline
registry_persistence.json
startup_items.txt
dll_hijack.txt