Skip to content

Malware Persistence (analysis)

Persistence is how malware survives reboots and logoffs to keep access. When analyzing a sample, identifying its persistence mechanism is key: it says where it “lives” in the system, provides high-fidelity IOCs, and is the first thing to clean in incident response. This card catalogs Windows persistence mechanisms from an analysis and detection view. (Linux persistence is covered in Linux Persistence; AD, in Active Directory Persistence.)

# auto-start (autoruns)
Run / RunOnce keys HKLM\...\CurrentVersion\Run , HKCU\...\Run
Startup folder startup folder (shortcut/script)
Services a service that starts at boot (CreateService)
Scheduled Tasks scheduled tasks (schtasks / COM) -> very common
# stealthier techniques
WMI event subscription a WMI consumer triggered by a system event (fileless)
COM hijacking hijack a COM key so your DLL is loaded
DLL search order hijacking place a DLL where an app loads it before the legitimate one
Image File Execution Options (IFEO) an executable's "debugger" -> launches your payload
AppInit_DLLs / LSA / Winlogon keys that load DLLs into system processes
# bootkits/rootkits boot/kernel-level persistence (the deepest)

Scheduled tasks and Run keys are the most common; WMI and COM hijacking are stealthier and fileless.

# dynamic (see mal-dynamic): observe what the sample installs on execution
Autoruns (Sysinternals) LISTS all auto-start points -> compare before/after
Regshot registry diff: which new keys appeared
ProcMon capture the key/task/service write
# static (see mal-static): imports and strings revealing the mechanism
RegSetValueEx + "\\Run" -> Run key
CreateService -> service
ITaskScheduler / schtasks -> scheduled task
IWbemServices (WMI) -> WMI event subscription

Autoruns (Sysinternals) is the key tool: it enumerates all the system’s persistence points at a glance, and what the malware added stands out against the baseline.

# persistence gives high-fidelity IOCs for detection and cleanup:
- the name and path of the persisted executable/DLL
- the exact registry key / task name / service name
- the command it runs (often reveals LOLBins, -enc, paths)
# -> Sigma rules on service creation (7045), tasks (4698), Run keys
# telemetry
Sysmon process creation (1), registry (12/13), file creation (11)
Windows logs 7045 (new service), 4698 (new task), 4657 (registry change)
WMI logging for WMI event subscriptions
Autoruns + EDR periodic enumeration of persistence points vs baseline
# hunting
- compare hosts' autoruns against a known-good baseline
- tasks/services with obfuscated commands or invoking interpreters/LOLBins
- unsigned DLLs loaded from user paths
# persistence is the first thing to remove to cut access:
1. identify ALL mechanisms (there may be several/redundant)
2. remove the malicious keys/tasks/services/DLLs
3. remove the persisted payload
4. verify (re-analyze autoruns) and, for serious compromise, rebuild the host
# remember: if ONE mechanism went undetected, the malware returns
  • Monitor the persistence points (Sysmon + Autoruns + EDR) against a baseline.
  • Sigma rules on service/task creation and Run-key changes.
  • Least privilege (many mechanisms need admin) and application allowlisting.
  • DLL/driver signing and boot protection (Secure Boot) against bootkits.
  • Map to MITRE ATT&CK (TA0003 Persistence) for systematic coverage.
  • Autoruns/Regshot before and after running the sample
  • Identify ALL installed persistence mechanisms
  • Imports/strings revealing the mechanism (static)
  • Extract exact IOCs (key/task/service/path/command)
  • Stealthy mechanisms (WMI/COM/IFEO)?
  • Derive detections (Sigma: 7045/4698/Run keys)
  • Map to MITRE ATT&CK (TA0003)
  • Cleanup plan (all mechanisms → payload → verify)