awesome-malware-persistence
by Karneades
A curated list of awesome malware persistence tools and resources.
AI summary
Persistence tools
A curated collection of malware persistence techniques and tools to help detect and understand malicious activity.
- stars
- 189
- forks
- 12
- watching
- 4
- awesome lists
- 2
- entries
- 55
What's in the list
55 links in 19 sections, with live GitHub stats.activeno commit in 2y
Techniques / Generic
- MITRE ATT&CK tactic "TA0003 - Persistence"
MITRE ATT&CK tactic "TA0003 - Persistence"
forensic artifact repository
Forensic artifact repository covers persistence techniques in their artifacts
Sigma rules
Sigma rules which covers persistence techniques. You can even use filters such as or specifically for one technique
Techniques / Linux
- Linux Malware Persistence with Cron
Blog post about linux persistence using cron jobs
- Linux Persistence Techniques
List of persistence techniques
- Linux Red Team Persistence Techniques
List of persistence techniques
PANIX - Persistence Against *NIX - Features
List of persistence techniques
- Linux Detection Engineering - A primer on persistence mechanisms
List of Linux persistence mechanisms
ebpfkit
Rootkit leveraging eBPF
TripleCross
Rootkit leveraging eBPF
- Linux LKM Persistence
Rootkit leveraging Linux loadable kernel module (LKM)
Techniques / macOS
- theevilbit's series "Beyond the good ol' LaunchAgents"
List of macOS persistence beyond just the LaunchDaemons or LaunchAgents
KnockKnock
A persistence detection tool for macOS to scan for persistence mechanisms on macOS. Specific persistence locations are found in the folder, e.g. or
PoisonApple
Learn about various macOS persistence techniques by looking at the source code of PoisonApple
- How malware persists on macOS
List of macOS persistence mechanisms
Techniques / Windows
- Hexacorn's blog
Hexacorn's blog category for persistence category including the series "Beyond good ol' Run key"
- Autoruns
You can learn which Windows persistence mechanisms are checked by looking at the output of Autoruns on your own client. Categories and the different locations where things were found are seen in the output. A disassembly of Autoruns lists a subset of the entries which are scanned
PowerShell implementation of Autoruns
Another way to find Windows persistence locations is to look at the source code of the PowerShell version of Autoruns. Bonus: A history of the covered persistence locations for each Autoruns version is found at the end of the module file too, which is so awesome!
- Common malware persistence mechanisms
Different persistence mechanisms for different vectors are described
- Malware persistence techniques
Good summary of multiple persistence mechanisms, ranging from multiple registry keys to more advanced one, like COM hijacking
- Detecting & Removing an Attacker's WMI Persistence
Blog post about detecting and removing WMI persistence
- Windows Persistence using WinLogon
Blog post about abusing WinLogon
- Untangling Kovter's persistence methods
Blog post about Kovter's persistens methos, among others, hiding in registry. Another one is
- Persistence using GlobalFlags in Image File Execution Options – Hidden from Autoruns.exe
Blog post about abusing GlobalFlag for process execution
- Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response
Blog post about bootloader persistence
Techniques / Windows / Various blog posts about COM/CLSID hijacking
Techniques / Windows
- Hunting for persistence via Microsoft Exchange Server or Outlook
Blog post about Microsoft Exchange server persistence
Techniques / Cloud
- Shadow Linking: The Persistence Vector of SaaS Identity Threat
Abuse of additional identity providers to persist in an environment
- Persisting on Entra ID applications and User Managed Identities with Federated Credentials
Persist on Entra ID applications and User Managed Identities with Federated Credentials
Techniques / Firmware
- MoonBounce: the dark side of UEFI firmware
An in-depth write up about one particular UEFI bootkit
Persistence Removal / Generic
Awesome Incident Response
Use the tools and resources for security incident response, aimed to help security analysts and DFIR teams
Persistence Removal / Windows
PowerSponse
PowerSponse includes various commands for cleanup of persistence mechanisms
- Removing Backdoors – Powershell Empire Edition
Various blog posts handle the removal of WMI implants
- RegDelNull
Removal of registry keys with null bytes - used e.g. in run keys for evasion
Detection Testing / Generic
Atomic Red Team
Atomic Red Team supports also the MITRE ATT&CK persistence techniques, see e.g.
Detection Testing / Linux
PANIX
A highly customizable Linux persistence tool. Perform various persistence techniques against Linux systems, among others Debian and RHEL
Diamorphine
A loadable kernel module (LKM) rootkit for Linux Kernels (x86/x86_64 and ARM64)
Detection Testing / macOS
PoisonApple
Perform various persistence techniques on macOS
Detection Testing / Windows
hasherezade persistence demos
Various (also non standard) persistence methods used by malware for testing own detection, among others COM hijacking demo is found in the repo
Prevention / macOS
BlockBlock
A tool which provides continual protection by monitoring persistence locations and protects them accordingly. Similar to KnockKnock but for blocking
Collection / Generic
Awesome Forensics
Use the tools from this list which includes awesome free (mostly open source) forensic analysis tools and resources. They help collecting the persistence mechanisms at scale, e.g. by using remote forensics tools
- osquery
Query persistence mechanisms on clients
OSSEC
Use rules and logs from the HIDS to detection configuration changes
Collection / Linux
Linux Security and Monitoring Scripts
Security and monitoring scripts you can use to monitor your Linux installation for security-related events or for an investigation. Among other finding systemd unit files used for malware persistence
Collection / macOS
- KnockKnock
A tool to uncover persistently installed software in order to generically reveal such malware. See
- Dylib Hijack Scanner or DHS
A simple utility that will scan your computer for applications that are either susceptible to dylib hijacking or have been hijacked. See
Collection / Windows
- Autoruns
A powerful persistence collection tool on Windows is Autoruns. It collects different categories and persistence information from a live system and . There is a UI and a command line program and the output format can be set to CSV which can then be imported into your log collection system of choice
AutorunsToWinEventLog.ps1
Instead of using CSV output and copy these file to the server, you can use the AutorunsToWinEventLog script to convert the Autoruns output to Windows event logs and rely on standard Windows event log forwarding
PowerShell Autoruns
A PowerShell version of Autoruns
PersistenceSniper
Powershell module to hunt for persistence implanted in Windows machines
- RegRipper
Extracts various persistence mechanisms from the registry files directly
RECmd
Extract various persistence mechanisms, e.g. by using the config file to extract user's CLSID information
- KAPE
The tool allows collecting various predefined artifactgs using targets and modules, see which include persistence mechanisms, among others there's a collection of , and or a module
Nothing in this list matches your filter.
Featured in 2 awesome lists
Each link jumps to the spot where the list mentions awesome-malware-persistence.
More related projects
karneades/malware-persistence165
tonyphipps/meerkat436
withsecurelabs/leonidas535
netspi/esc283
palantir/alerting-detection-strategy-framework703
log2timeline/plaso1.7K
hausec/adape-script1.1K
spyre-project/spyre164
forensicartifacts/artifacts-kb75
mdecrevoisier/evtx-to-mitre-attack532
withsecurelabs/chainsaw2.9K
splunk/attack_range2.2K