Malware Persistence (analysis)
Persistence is how malware survives reboots and logoffs to keep access. When analyzing a sample, identifying its persistence mechanism is key: it says where it “lives” in the system, provides high-fidelity IOCs, and is the first thing to clean in incident response. This card catalogs Windows persistence mechanisms from an analysis and detection view. (Linux persistence is covered in Linux Persistence; AD, in Active Directory Persistence.)
Windows persistence mechanisms
Section titled “Windows persistence mechanisms”# auto-start (autoruns)Run / RunOnce keys HKLM\...\CurrentVersion\Run , HKCU\...\RunStartup folder startup folder (shortcut/script)Services a service that starts at boot (CreateService)Scheduled Tasks scheduled tasks (schtasks / COM) -> very common# stealthier techniquesWMI event subscription a WMI consumer triggered by a system event (fileless)COM hijacking hijack a COM key so your DLL is loadedDLL search order hijacking place a DLL where an app loads it before the legitimate oneImage File Execution Options (IFEO) an executable's "debugger" -> launches your payloadAppInit_DLLs / LSA / Winlogon keys that load DLLs into system processes# bootkits/rootkits boot/kernel-level persistence (the deepest)Scheduled tasks and Run keys are the most common; WMI and COM hijacking are stealthier and fileless.
Detect persistence when analyzing
Section titled “Detect persistence when analyzing”# dynamic (see mal-dynamic): observe what the sample installs on executionAutoruns (Sysinternals) LISTS all auto-start points -> compare before/afterRegshot registry diff: which new keys appearedProcMon capture the key/task/service write# static (see mal-static): imports and strings revealing the mechanismRegSetValueEx + "\\Run" -> Run keyCreateService -> serviceITaskScheduler / schtasks -> scheduled taskIWbemServices (WMI) -> WMI event subscriptionAutoruns (Sysinternals) is the key tool: it enumerates all the system’s persistence points at a glance, and what the malware added stands out against the baseline.
As an analyst: extract the IOC
Section titled “As an analyst: extract the IOC”# persistence gives high-fidelity IOCs for detection and cleanup:- the name and path of the persisted executable/DLL- the exact registry key / task name / service name- the command it runs (often reveals LOLBins, -enc, paths)# -> Sigma rules on service creation (7045), tasks (4698), Run keysHunting and detection (blue team)
Section titled “Hunting and detection (blue team)”# telemetrySysmon process creation (1), registry (12/13), file creation (11)Windows logs 7045 (new service), 4698 (new task), 4657 (registry change)WMI logging for WMI event subscriptionsAutoruns + EDR periodic enumeration of persistence points vs baseline# hunting- compare hosts' autoruns against a known-good baseline- tasks/services with obfuscated commands or invoking interpreters/LOLBins- unsigned DLLs loaded from user pathsResponse (cleanup)
Section titled “Response (cleanup)”# persistence is the first thing to remove to cut access:1. identify ALL mechanisms (there may be several/redundant)2. remove the malicious keys/tasks/services/DLLs3. remove the persisted payload4. verify (re-analyze autoruns) and, for serious compromise, rebuild the host# remember: if ONE mechanism went undetected, the malware returnsFor the defense
Section titled “For the defense”- Monitor the persistence points (Sysmon + Autoruns + EDR) against a baseline.
- Sigma rules on service/task creation and Run-key changes.
- Least privilege (many mechanisms need admin) and application allowlisting.
- DLL/driver signing and boot protection (Secure Boot) against bootkits.
- Map to MITRE ATT&CK (TA0003 Persistence) for systematic coverage.
Testing checklist (analysis)
Section titled “Testing checklist (analysis)”- Autoruns/Regshot before and after running the sample
- Identify ALL installed persistence mechanisms
- Imports/strings revealing the mechanism (static)
- Extract exact IOCs (key/task/service/path/command)
- Stealthy mechanisms (WMI/COM/IFEO)?
- Derive detections (Sigma: 7045/4698/Run keys)
- Map to MITRE ATT&CK (TA0003)
- Cleanup plan (all mechanisms → payload → verify)