Persistence Mechanism
Definition
The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron jobs on Linux, and boot-sector modification. Persistence artefacts are often the most durable evidence on an infected system.
- Purpose
- Survive reboot or user logout
- Windows examples
- Registry run keys, scheduled tasks, services
- Linux examples
- Cron jobs, systemd units, boot-sector modification
- Forensic value
- Often the most durable artefact on an infected host
- Detection approach
- Baseline comparison against a known-clean system
Common questions
Why are persistence mechanisms often the most useful artefact for investigators?+
Process memory and network connections vanish at shutdown, but a registry run key or scheduled task sits on disk indefinitely, so it can still be recovered and analysed weeks after the initial infection even if the malware process itself was never captured running.
Do all malware families need a persistence mechanism?+
No. Some malware, particularly fileless or memory-resident variants used for short smash-and-grab operations, deliberately avoids persistence to reduce its forensic footprint, which is itself a useful indicator when investigators find no persistence artefacts despite other signs of compromise.
How do investigators distinguish a malicious scheduled task from a legitimate one?+
They compare the task against a known-good baseline for that operating system version, check whether the executable it calls is signed and located in an expected system directory, and look at the task's creation timestamp against the suspected compromise window.
Related terms
- Command and Control (C2)
- The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from...
- Configuration Drift
- Deviation from an approved baseline configuration, whether caused by legitimate administrative action or by an attacker modifying settings to weaken defences or...
- Dropper
- A malware component whose sole function is to deliver and install a secondary payload. The dropper itself may be a trojan, a...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Payload
- The action the malware performs once active: data encryption (ransomware), credential theft (banking trojan), resource hijacking (cryptominer), or system destruction (wiper). The...
- Propagation Mechanism
- The method by which malware copies itself to new hosts. Viruses attach to host files; worms exploit network services autonomously; trojans rely...
- Reimaging
- Wiping a compromised system and restoring it from a known-good operating system image. Reimaging is the most reliable eradication method for host-level...
- Rogue Account
- A user or service account created by the attacker during the intrusion to maintain access independent of any compromised legitimate account. Rogue...
- Rootkit
- Malware designed to hide its own presence by subverting the operating system's reporting functions. User-mode rootkits hook API calls; kernel-mode rootkits modify...
- Web Shell
- A script (typically PHP, ASP, or JSP) placed on a web server by an attacker to provide remote command execution via HTTP...
Explained in these topics
- Malware Taxonomy: Viruses, Trojans, Ransomware and More
- Threat Eradication MethodsAny method by which an attacker maintains access to a system across reboots, logoffs, or credential changes. Examples include malicious scheduled tasks, regist...