Windows Persistence Explained: Techniques, Risks, and What Defenders Should Know
ID: 8cd02105-26b0-557f-84ee-c371eff3021b
STIX ID: report--8cd02105-26b0-557f-84ee-c371eff3021b
Feed Name: Cofense Blog
This report explains how threat actors maintain persistence on Windows by abusing legitimate features—such as registry Run/Winlogon entries, user and common Startup folders, Scheduled Tasks, and Windows Services—to ensure malware executes on login or specific system events. It discusses tactics like fileless payloads stored in the registry and nuances of RunOnce behavior, and points to forensic artifacts (e.g., registry hives and task XML definitions) useful for detection. The report concludes with practical guidance for threat hunting and mitigation, including EDR monitoring, autoruns baselining, and the use of Sysinternals Autoruns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
