persistence-info / persistence-info.github.io

Home Page:https://persistence-info.github.io/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

The repository tries to gather an information about Windows persistence mechanisms to make the protection/detection more efficient. Most of the information is well known for years, being actively used within various scenarios.
Expect more. I am doing my best to add new entries each day.

How it works. And how to contribute.


πŸ‘¨β€πŸ’Ό HKCU Run and RunOnce registry keys

πŸ‘¨β€πŸ’Ό βš™ Task Scheduler

βš™ Image File Execution Options key

βš™ Windows Services

AeDebug

WER Debugger *

βš™ Natural Language Development Platform 6 DLLs *

βš™ GPO Client-side Extension

βš™ Filter Handlers for Windows Search

Disk Cleanup Handler

πŸ‘¨β€πŸ’Ό .chm helper DLL *

hhctrl.ocx *

βš™ AMSI Providers

βš™ ServerLevelPluginDll

Password Filter

Credential Manager DLL

βš™ Authentication Packages

Code Signing DLL

πŸ‘¨β€πŸ’Ό HKCU cmd.exe AutoRun

βš™ LSA Extension

βš™ Winlogon Notification Package

βš™ Print Monitor

πŸ‘¨β€πŸ’Ό HKCU Load

MPNotify

βš™ Windows Platform Binary Table

Explorer tools *

πŸ‘¨β€πŸ’Ό Windows Terminal Profile

πŸ‘¨β€πŸ’Ό Startup Folder

πŸ‘¨β€πŸ’Ό User Init Mpr Logon Script *

βš™ Autodial DLL *

.NET Startup Hooks

πŸ‘¨β€πŸ’Ό PowerShell Profiles

πŸ‘¨β€πŸ’Ό TS Initial Program

RDP WDS Startup Programs

βš™ IFilter

Recycle Bin COM Extension Handler *

TelemetryController

Monitoring Silent Process Exit

βš™ Desired State Configuration

πŸ‘¨β€πŸ’Ό Screen Saver

Netsh extension DLL

βš™ Boot Verification Program

πŸ‘¨β€πŸ’Ό File Extension Hijacking

πŸ‘¨β€πŸ’Ό Keyboard Shortcut *

Want more? Check the list tomorrow. :)


* Based on a research made by @Hexacorn - one of the best persistence hunters.

βš™ It is enough to turn computer on to make the code run.
πŸ‘¨β€πŸ’Ό End-user can do it.

About

https://persistence-info.github.io/

License:GNU General Public License v3.0