performing-malware-persistence-investigation - Investigate malware persistence across Windows and Linux
Systematically investigates Windows and Linux persistence mechanisms to identify how malware survives reboots and maintains access.
Tags
Updated: 2026-10-04Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Enumerate registry persistence
- Analyze scheduled task XML
- Inspect WMI event subscriptions
- Check startup folder contents
- Detect DLL search hijacking
- Inspect COM object hijacking
- Scan persistence locations
- Compare autorun entries
- Verify persistence removal
Inputs
- Forensic image
- Live system access
- Known-good autorun baseline
- YARA rules
Outputs
- registry_persistence.json
- startup_items.txt
- dll_hijack.txt
- Copied scheduled task files
- Copied WMI repository files
- Persistence findings
Requirements
- Administrative privileges
- Windows and Linux persistence knowledge
- Sysinternals Autoruns
- RegRipper
- Python Registry library
- YARA scanning support
- PyWMIPersistenceFinder
