Open cardosec

Case D6B1EB · Malware & intel · L2 Practitioner

Windows persistence mechanisms

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Registry Run/RunOnce keys under HKCU/HKLM Software\Microsoft\Windows\CurrentVersion are the classic choice
  2. Scheduled tasks (Event 4698) and new services (System Event 7045) survive reboots and can run as SYSTEM
  3. WMI event subscriptions (filter + consumer binding) are fileless and often missed by basic tooling
  4. Other options: startup folder, DLL search-order hijacking, COM hijacking, Winlogon Shell/Userinit values
  5. Hunt with Sysinternals Autoruns, Sysmon events 12/13 (registry) and 19-21 (WMI), and baseline diffs

If the interviewer pushes back

  • Which persistence mechanisms survive a password reset and a reimage of the user profile but not a full rebuild?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.