reg_hunter

Persistence hunter

A tool for triaging and hunting Windows persistence mechanisms, providing forensic insights into system activity.

Blueteam operational triage registry hunting/forensic tool.

GitHub

143 stars
6 watching
19 forks
Language: Rust
last commit: over 3 years ago

Related projects:

RepositoryDescriptionStars
last-byte/persistencesniperAutomated detection of malicious persistence techniques in Windows machines.1,930
joeavanzato/trawlerA PowerShell script designed to help Incident Responders discover potential indicators of compromise on Windows hosts by scanning for various persistence techniques.310
n4kedturtle/persistbofA tool to automate common persistence mechanisms across various Windows environments269
karneades/malware-persistenceA collection of information on malware persistence mechanisms and techniques.165
0xthirteen/staykitA persistence kit for Cobalt Strike using a custom .NET assembly and leveraging various Windows techniques to maintain access after initial access is lost.468
aegrah/panixA modular Linux persistence framework providing various techniques to achieve persistent access on Linux systems465
zonksec/persistence-aggressor-scriptA PowerShell script designed to evade detection by persisting on a compromised system through multiple evasion techniques173
ntraiseharderror/kaiserToolset providing fileless persistence and anti-forensic capabilities for Windows 787
ewhitehats/invisiblepersistenceA Windows registry persistence mechanism that operates stealthily339
outflanknl/sharphideCreates hidden registry keys to persist data despite DFIR investigation468
rabite0/hunterA fast and feature-rich file browser built on top of Rust, providing an efficient terminal-based interface for managing files and directories.1,326
cyborgsecurity/poisonappleA command-line tool for simulating and demonstrating persistence techniques on macOS systems.221
hasherezade/persistence_demosDemonstrates various persistence methods used by malware219
beahunt3r/windows-huntingA collection of tools and resources to aid Windows threat hunters in identifying common security artifacts.347
teknasyon-teknoloji/persistencekitA library providing a simple way to store and retrieve Codable objects in various persistence layers154