PersistenceSniper

Persistence detector

Automated detection of malicious persistence techniques in Windows machines.

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte

GitHub

2k stars
42 watching
189 forks
Language: PowerShell
last commit: almost 2 years ago
Linked from 1 awesome list

incident-responsemalware-detectionpersistencepowershellpowershell-modulepowershell-scriptregistrytechniqueswindows

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
joeavanzato/trawlerA PowerShell script designed to help Incident Responders discover potential indicators of compromise on Windows hosts by scanning for various persistence techniques.310
zonksec/persistence-aggressor-scriptA PowerShell script designed to evade detection by persisting on a compromised system through multiple evasion techniques173
theflakes/reg_hunterA tool for triaging and hunting Windows persistence mechanisms, providing forensic insights into system activity.143
threatexpress/persistence-aggressor-scriptA tool for creating and managing persistent malware components that can operate in multiple listener scenarios, including local and foreign listeners.42
ntraiseharderror/kaiserToolset providing fileless persistence and anti-forensic capabilities for Windows 787
aegrah/panixA modular Linux persistence framework providing various techniques to achieve persistent access on Linux systems465
karneades/malware-persistenceA collection of information on malware persistence mechanisms and techniques.165
cyborgsecurity/poisonappleA command-line tool for simulating and demonstrating persistence techniques on macOS systems.221
ewhitehats/invisiblepersistenceA Windows registry persistence mechanism that operates stealthily339
0xthirteen/staykitA persistence kit for Cobalt Strike using a custom .NET assembly and leveraging various Windows techniques to maintain access after initial access is lost.468
hasherezade/persistence_demosDemonstrates various persistence methods used by malware219
objective-see/blockblockProvides continual protection by monitoring persistence locations across multiple platforms650
netspi/pesecurityA PowerShell module to analyze Windows binary files for various security features and compilation settings.626
teknasyon-teknoloji/persistencekitA library providing a simple way to store and retrieve Codable objects in various persistence layers154
d4stiny/peacemakerA Windows kernel-mode utility designed to detect and analyze advanced malware techniques.417