mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
4.6 KiB
4.6 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | ||||
|---|---|---|---|---|---|---|---|
| Windows Persistence Techniques | 2018-05-31 | true |
|
Description
Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment.
- ID: 30874d4f-20a1-488f-85ec-5d52ef74e3f9
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2018-05-31
- Author: Bhavin Patel, Splunk
Detection profiles
Reference
- http://www.fuzzysecurity.com/tutorials/19.html
- https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html
- http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
- https://www.youtube.com/watch?v=dq2Hv7J9fvk
source | version: 2