Search and filter across all detection sources
1,886 rules
[CROWDSTRIKE] Possible Persistence Attempt Blocked - Suspicious Registry Change Indicating Malicious Persistence Mechanism
[CROWDSTRIKE] Possible Persistence Attempt Detected - Suspicious Registry Change Indicating Malicious Persistence Mechanism
[CROWDSTRIKE] Possible Persistence Attempt Killed - Suspicious Registry Change Indicating Malicious Persistence Mechanism
Potential Persistence Using DebugPath
Detects potential persistence using Appx DebugPath
[CROWDSTRIKE] Persistence Tactic Catchall
[MICROSOFT-ATP] Persistence alert
ps1_toolkit_Persistence [yara]
Auto-generated rule - file Persistence.ps1
[CISCO-SCA] AWS Lambda Persistence
Persistence via Kernel Module Modification
Identifies loadable kernel module errors, which are often indicative of potential persistence attempts.
Registry Persistence Mechanisms in Recycle Bin
Detects persistence registry keys for Recycle Bin
ps1_toolkit_Persistence_2 [yara]
Auto-generated rule - from files Persistence.ps1
[CISCO-SCA] AWS Temporary Token Persistence
[CISCO-SCA] Persistent Remote Control Connections
Empire_Persistence [yara]
Empire - a pure PowerShell post-exploitation agent - file Persistence.psm1
HvS_APT27_HyperBro_Stage3_Persistence [yara]
HyperBro Stage 3 registry keys for persistence
install_get_persistent_filenames [yara]
EQGRP Toolset Firewall - file install_get_persistent_filenames
Persistence_Agent_MacOS [yara]
Detects a Python agent that establishes persistence on macOS
install_get_persistent_filenames [malware]
[MICROSOFT_DEFENDER_ENDPOINT] Persistence High Alert Detected
[MICROSOFT_DEFENDER_ENDPOINT] Persistence Informational Alert Detected
[MICROSOFT_DEFENDER_ENDPOINT] Persistence Low Alert Detected