Glossary

Persistence

Persistence is how attackers stay even after you restart or change passwords. They might add themselves to startup, create scheduled tasks, or install services. Finding all persistence mechanisms is key to truly removing an attacker.

What is Persistence?

Techniques attackers use to maintain access to a compromised system even after reboots, credential changes, or other disruptions.

Why Should You Care?

Without persistence, attackers are evicted from systems through routine maintenance—reboots, updates, credential rotations. When an attacker establishes persistence, incident response teams face a far harder problem: they must hunt for every installation point or risk re-compromise immediately after remediation. This dramatically increases the cost and time of incident response, and organizations that miss even one persistence mechanism often experience repeat breaches within days or weeks.

Is your business exposed?

Real-World Example

During the SolarWinds supply-chain attack, adversaries installed persistence mechanisms—such as scheduled tasks and registry run keys—that allowed them to maintain access even after patches were applied and initial malware was removed. Security teams who only removed the initial infection vector found themselves dealing with the same attackers again later, having to restart containment from scratch.

How to Protect Against Persistence

  1. 1.

    Audit startup programs and scheduled tasks

  2. 2.

    After breaches, check all persistence locations

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required