What problem does it solve?
This Skill solves the critical gap of identifying long-term attacker footholds in Windows memory dumps that survive system reboots and re-imaging, which is essential for effective post-intrusion scoping and complete incident cleanup.
Core Features & Use Cases
- Comprehensive Persistence Enumeration: Detects 11 common Windows persistence mechanisms including registry autoruns, services, scheduled tasks, WMI event subscriptions, COM hijacks, IFEO, AppInit DLLs, and kernel drivers.
- MITRE ATT&CK Mapping: Automatically links identified persistence artifacts to official MITRE ATT&CK technique IDs for standardized, actionable reporting.
- Use Case: During a confirmed corporate intrusion, use this Skill to scan acquired memory dumps for all persistence artifacts, determine which footholds will survive a full system re-image, and prioritize cleanup efforts to prevent attacker re-access.
Quick Start
Use the persistence-hunt skill to scan a provided Windows memory dump for all persistence mechanisms and generate a prioritized list of surviving artifacts with their associated MITRE ATT&CK technique IDs.