Persistence methods
by ghjuyetmolyuiw - Friday August 4, 2023 at 07:47 PM
#1
Which method is your go to when it comes to persistence?

I'm familiar with the basics in Windows, like:

- Dropping something in the Startup directory.
- Go to the registry and modify the Run and RunOnce keys.
- DLL Hijacking & DLL Proxying

But, what other methods do you know?

Would you recommend one over the other? Why?

And for Linux? Which is your go to?
Reply
#2
I will use a combination of registry keys.

1 - Dropping a registry key to autostart an exe like random2.exe
2 - Then drop a second registry key at IFEO to debug ransom2.exe and point to the right exe

It's called registry hive...
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: 2.4) Survey, URL Shorteners, Referral links, or any type of "monetized" links are not allowed. This includes upload websites where you earn money for sharing a download.
Reply
#3
(08-06-2023, 03:36 PM)hacxx Wrote: I will use a combination of registry keys.

1 - Dropping a registry key to autostart an exe like random2.exe
2 - Then drop a second registry key at IFEO to debug ransom2.exe and point to the right exe

It's called registry hive...

I will take a look at it, thanks!

(08-11-2023, 07:44 PM)Zed55 Wrote: If you need some idea, check this :
https://attack.mitre.org/tactics/TA0003/

But there is schtasks, services, BITS jobs etc ...

That's a good starting point, I should have started by looking there lol. Thanks!
Reply
#4
(08-11-2023, 07:44 PM)Zed55 Wrote: If you need some idea, check this :
https://attack.mitre.org/tactics/TA0003/

But there is schtasks, services, BITS jobs etc ...

Thanks, BITS it's a bit old and at the moment i'm not into malware.
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: 2.4) Survey, URL Shorteners, Referral links, or any type of "monetized" links are not allowed. This includes upload websites where you earn money for sharing a download.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Efficient Methods for Searching Large Text and Compressed Files breachxyz 3 430 10-06-2024, 03:45 AM
Last Post: Breach_Forums
  Reliable Caller ID Spoofing Methods? 5kidw4rd 0 347 08-22-2024, 06:38 PM
Last Post: 5kidw4rd
  Methods to exchange dirty cash for xmr? $500k 1m2mzapq 0 639 02-07-2024, 01:47 AM
Last Post: 1m2mzapq

Forum Jump:


 Users browsing this thread: