Skip to content

Latest commit

Β 

History

History
111 lines (57 loc) Β· 3.23 KB

README.md

File metadata and controls

111 lines (57 loc) Β· 3.23 KB

The repository tries to gather an information about Windows persistence mechanisms to make the protection/detection more efficient. Most of the information is well known for years, being actively used within various scenarios.
Expect more. I am doing my best to add new entries each day.

How it works. And how to contribute.


πŸ‘¨β€πŸ’Ό HKCU Run and RunOnce registry keys

πŸ‘¨β€πŸ’Ό βš™ Task Scheduler

βš™ Image File Execution Options key

βš™ Windows Services

AeDebug

WER Debugger *

βš™ Natural Language Development Platform 6 DLLs *

βš™ GPO Client-side Extension

βš™ Filter Handlers for Windows Search

Disk Cleanup Handler

πŸ‘¨β€πŸ’Ό .chm helper DLL *

hhctrl.ocx *

βš™ AMSI Providers

βš™ ServerLevelPluginDll

Password Filter

Credential Manager DLL

βš™ Authentication Packages

Code Signing DLL

πŸ‘¨β€πŸ’Ό HKCU cmd.exe AutoRun

βš™ LSA Extension

βš™ Winlogon Notification Package

βš™ Print Monitor

πŸ‘¨β€πŸ’Ό HKCU Load

MPNotify

βš™ Windows Platform Binary Table

Explorer tools *

πŸ‘¨β€πŸ’Ό Windows Terminal Profile

πŸ‘¨β€πŸ’Ό Startup Folder

πŸ‘¨β€πŸ’Ό User Init Mpr Logon Script *

βš™ Autodial DLL *

.NET Startup Hooks

πŸ‘¨β€πŸ’Ό PowerShell Profiles

πŸ‘¨β€πŸ’Ό TS Initial Program

RDP WDS Startup Programs

βš™ IFilter

Recycle Bin COM Extension Handler *

TelemetryController

Monitoring Silent Process Exit

βš™ Desired State Configuration

πŸ‘¨β€πŸ’Ό Screen Saver

Netsh extension DLL

βš™ Boot Verification Program

πŸ‘¨β€πŸ’Ό File Extension Hijacking

πŸ‘¨β€πŸ’Ό Keyboard Shortcut *

Want more? Check the list tomorrow. :)


* Based on a research made by @Hexacorn - one of the best persistence hunters.

βš™ It is enough to turn computer on to make the code run.
πŸ‘¨β€πŸ’Ό End-user can do it.