Skip to content
76

Awesome Malware Persistence

A curated list of awesome malware persistence tools and resources.

310 stars21 forks56 entriesLast push Aug 25, 2026 (1 month ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

General

Main article about malware persistence

with more context and information.

In 3 lists

Techniques >Generic

MITRE ATT&CK tactic "TA0003 - Persistence"

Persistence tactic information in the MITRE ATT&CK framework.

Forensic Artifact repository

A free, community-sourced, machine-readable knowledge base of digital forensic artifacts.

In 3 lists

Sigma rules

Repository of detection rules, covering persistence techniques as well. You can even use filters such as --filter tag=attack.persistence or specifically for one technique tag=attack.t1084.

In 2 lists

Techniques >Linux

Linux Malware Persistence with Cron

Blog post about Linux persistence using cron jobs.

Linux Persistence Techniques

List of persistence techniques.

Linux Red Team Persistence Techniques

List of persistence techniques.

In 2 lists

PANIX - Persistence Against *NIX - Features

List of persistence techniques.

Linux Detection Engineering - A primer on persistence mechanisms

List of Linux persistence mechanisms.

ebpfkit

Rootkit leveraging eBPF.

In 3 lists

TripleCross

Rootkit leveraging eBPF.

In 6 listsDetails

Linux LKM Persistence

Rootkit leveraging Linux loadable kernel module (LKM).

Techniques >macOS

theevilbit's series "Beyond the good ol' LaunchAgents"

List of macOS persistence beyond just the LaunchDaemons or LaunchAgents.

KnockKnock

A persistence detection tool for macOS to scan for persistence mechanisms on macOS. Specific persistence locations are found in the plugins folder, e.g. LaunchItems or StartupScripts.

PoisonApple

Learn about various macOS persistence techniques by looking at the source code of PoisonApple.

How malware persists on macOS

List of macOS persistence mechanisms.

Techniques >Windows

Hexacorn's blog

Blog series "Beyond good ol' Run key" covering a lot of Windows persistence mechanisms.

Autoruns

You can learn which Windows persistence mechanisms are checked by looking at the output of Autoruns on your own client. Categories and the different locations where things were found are seen in the output. A disassembly of Autoruns lists a subset of the entries which are scanned.

PowerShell implementation of Autoruns

Another way to find Windows persistence locations is to look at the source code of the PowerShell version of Autoruns. Bonus: A history of the covered persistence locations for each Autoruns version is found at the end of the module file too, which is so awesome!

Common malware persistence mechanisms

Different persistence mechanisms for different vectors are described.

Malware persistence techniques

Good summary of multiple persistence mechanisms, ranging from multiple registry keys to more advanced one, like COM hijacking.

Detecting & Removing an Attacker's WMI Persistence

Blog post about detecting and removing WMI persistence.

Windows Persistence using WinLogon

Blog post about abusing WinLogon.

Untangling Kovter's persistence methods

Blog post about Kovter's persistens methos, among others, hiding in registry. Another one is Threat Spotlight: Kovter Malware Fileless Persistence Mechanism.

Persistence using GlobalFlags in Image File Execution Options – Hidden from Autoruns.exe

Blog post about abusing GlobalFlag for process execution.

Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response

Blog post about bootloader persistence.

COM Object hijacking: the discreet way of persistence, 2014

Persistence – COM Hijacking, 2020

Abusing COM hijacking in combination with scheduled tasks, 2016

Hunting for persistence via Microsoft Exchange Server or Outlook

Blog post about Microsoft Exchange server persistence.

Borrowing Windows Hello keys for authentication and persistence

Ability to perform single-sign on with the backing cryptographic Windows Hello keys from a user session, without needing the PIN or other information/user presence.

Techniques >Cloud

Shadow Linking: The Persistence Vector of SaaS Identity Threat

Abuse of additional identity providers to persist in an environment.

Persisting on Entra ID applications and User Managed Identities with Federated Credentials

Persist on Entra ID applications and User Managed Identities with Federated Credentials.

AWSDoor: Persistence on AWS

Access persistence tool for AWS. The corresponding article describes the techniques adversaries can use to hide themselves within a cloud environment and its AWSDoor implementation to simplify and automate the deployment of persistence techniques in AWS environments.

Techniques >Firmware

MoonBounce: the dark side of UEFI firmware

An in-depth write up about one particular UEFI bootkit.

Techniques >Databases

Database Triggers as Persistence Mechanisms

An in-depth write up about database triggers providing persistence.

Persistence Removal >Windows

PowerSponse

A incident response tool covering various commands for cleanup of persistence mechanisms as well.

In 2 lists

Removing Backdoors – Powershell Empire Edition

Various blog posts handle the removal of WMI implants.

RegDelNull

Removal of registry keys with null bytes - used e.g. in run keys for evasion.

Detection Testing >Generic

Atomic Red Team

A red team attack techniques framework supporting also the MITRE ATT&CK persistence techniques, see e.g. T1044 "File System Permissions Weakness".

In 6 listsDetails

Detection Testing >Linux

PANIX - Persistence Against *NIX - Features

List of persistence techniques.

Diamorphine

A loadable kernel module (LKM) rootkit for Linux Kernels (x86/x86_64 and ARM64).

In 4 lists

Detection Testing >macOS

PoisonApple

Learn about various macOS persistence techniques by looking at the source code of PoisonApple.

Detection Testing >Windows

hasherezade persistence demos

Various (also non standard) persistence methods used by malware for testing own detection, among others COM hijacking demo is found in the repo.

Prevention >macOS

BlockBlock

A tool which provides continual protection by monitoring persistence locations and protects them accordingly. Similar to KnockKnock but for blocking.

Collection >Generic

Awesome Forensics

Use the tools from this list which includes awesome free (mostly open source) forensic analysis tools and resources. They help collecting the persistence mechanisms at scale, e.g. by using remote forensics tools.

In 5 listsDetails

osquery

Query persistence mechanisms on clients.

OSSEC

Use rules and logs from the HIDS to detection configuration changes.

In 6 listsDetails

Collection >Linux

Linux Security and Monitoring Scripts

Security and monitoring scripts you can use to monitor your Linux installation for security-related events or for an investigation. Among other finding systemd unit files used for malware persistence.

Collection >macOS

KnockKnock

A tool to uncover persistently installed software in order to generically reveal such malware. See GitHub repository too for the source code.

In 4 listsDetails

Dylib Hijack Scanner or DHS

A simple utility that will scan your computer for applications that are either susceptible to dylib hijacking or have been hijacked. See GitHub repository too for the source code.

In 3 lists

Collection >Windows

Autoruns

A powerful persistence collection tool on Windows is Autoruns. It collects different categories and persistence information from a live system and in limited ways from offline images. There is a UI and a command line program and the output format can be set to CSV which can then be imported into…

AutorunsToWinEventLog.ps1

Instead of using CSV output and copy these file to the server, you can use the AutorunsToWinEventLog script to convert the Autoruns output to Windows event logs and rely on standard Windows event log forwarding.

PowerShell implementation of Autoruns

Another way to find Windows persistence locations is to look at the source code of the PowerShell version of Autoruns. Bonus: A history of the covered persistence locations for each Autoruns version is found at the end of the module file too, which is so awesome!

PersistenceSniper

Powershell module to hunt for persistence implanted in Windows machines.

In 2 lists

RegRipper

Extracts various persistence mechanisms from the registry files directly.

In 2 lists

RECmd

Extract various persistence mechanisms, e.g. by using the config file UserClassesASEPs to extract user's CLSID information.

KAPE

The tool allows collecting various predefined artifactgs using targets and modules, see KapeFiles which include persistence mechanisms, among others there's a collection of LNK files, scheduled task files and scheduled task listing or a WMI repository auditing module.

In 2 lists

PyrsistenceSniper

A Python-based offline Windows persistence detection tool. Point it at a KAPE dump, a Velociraptor collection, or a mounted disk image and get offline Windows persistence detection. Runs on Windows, Linux, and macOS.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
88

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k563 entriesPushed 27 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago