Awesome Lists

awesome-malware-persistence

by Karneades

awesome listpushed almost 2 years ago

A curated list of awesome malware persistence tools and resources.

AI summary

Persistence tools

A curated collection of malware persistence techniques and tools to help detect and understand malicious activity.

stars
189
forks
12
watching
4
awesome lists
2
entries
55
View on GitHub

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/Karneades/awesome-malware-persistence/links.svg)](https://awesome.facts.dev/awesome/Karneades/awesome-malware-persistence)
HTML
<a href="https://awesome.facts.dev/awesome/Karneades/awesome-malware-persistence"><img src="https://awesome.facts.dev/shield/Karneades/awesome-malware-persistence/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/Karneades/awesome-malware-persistence/links.svg

What's in the list

55 links in 19 sections, with live GitHub stats.activeno commit in 2y

Techniques / Generic

Techniques / Linux

Techniques / macOS

Techniques / Windows

Techniques / Windows / Various blog posts about COM/CLSID hijacking

Techniques / Windows

Techniques / Cloud

Techniques / Firmware

Persistence Removal / Generic

  • Awesome Incident Response

    Use the tools and resources for security incident response, aimed to help security analysts and DFIR teams

Persistence Removal / Windows

Detection Testing / Generic

  • Atomic Red Team

    Atomic Red Team supports also the MITRE ATT&CK persistence techniques, see e.g.

Detection Testing / Linux

  • PANIX

    A highly customizable Linux persistence tool. Perform various persistence techniques against Linux systems, among others Debian and RHEL

  • Diamorphine

    A loadable kernel module (LKM) rootkit for Linux Kernels (x86/x86_64 and ARM64)

Detection Testing / macOS

  • PoisonApple

    Perform various persistence techniques on macOS

Detection Testing / Windows

  • hasherezade persistence demos

    Various (also non standard) persistence methods used by malware for testing own detection, among others COM hijacking demo is found in the repo

Prevention / macOS

  • BlockBlock

    A tool which provides continual protection by monitoring persistence locations and protects them accordingly. Similar to KnockKnock but for blocking

Collection / Generic

  • Awesome Forensics

    Use the tools from this list which includes awesome free (mostly open source) forensic analysis tools and resources. They help collecting the persistence mechanisms at scale, e.g. by using remote forensics tools

  • osquery

    Query persistence mechanisms on clients

  • OSSEC

    Use rules and logs from the HIDS to detection configuration changes

Collection / Linux

  • Linux Security and Monitoring Scripts

    Security and monitoring scripts you can use to monitor your Linux installation for security-related events or for an investigation. Among other finding systemd unit files used for malware persistence

Collection / macOS

  • KnockKnock

    A tool to uncover persistently installed software in order to generically reveal such malware. See

  • Dylib Hijack Scanner or DHS

    A simple utility that will scan your computer for applications that are either susceptible to dylib hijacking or have been hijacked. See

Collection / Windows

  • Autoruns

    A powerful persistence collection tool on Windows is Autoruns. It collects different categories and persistence information from a live system and . There is a UI and a command line program and the output format can be set to CSV which can then be imported into your log collection system of choice

  • AutorunsToWinEventLog.ps1

    Instead of using CSV output and copy these file to the server, you can use the AutorunsToWinEventLog script to convert the Autoruns output to Windows event logs and rely on standard Windows event log forwarding

  • PowerShell Autoruns

    A PowerShell version of Autoruns

  • PersistenceSniper

    Powershell module to hunt for persistence implanted in Windows machines

  • RegRipper

    Extracts various persistence mechanisms from the registry files directly

  • RECmd

    Extract various persistence mechanisms, e.g. by using the config file to extract user's CLSID information

  • KAPE

    The tool allows collecting various predefined artifactgs using targets and modules, see which include persistence mechanisms, among others there's a collection of , and or a module

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.