Hunting For Persistence Mechanisms In Windows

Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions. Use when performing a broad persistence sweep during incident response or building SIEM detections that cover the full range of Windows persistence techniques (MITRE T1547).

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/hunting-for-persistence-mechanisms-in-windows commit 62bc71e1d9

Frequently asked questions

npx skillmds@latest add gabrielmoreira/hunting-for-persistence-mechanisms-in-windows