Persistence Detection Rules | Fibratus
Detection rules for Persistence (MITRE ATT&CK): registry run keys, startup folders, port monitors, print processors, and service-based persistence.
Rules in this category
- Executable file dropped by an unsigned service DLL
- Hidden local account creation
- Network connection via startup folder executable or script
- Potential mandatory profile registry persistence
- Potential port monitor or print processor persistence via registry modification
- RID Hijacking
- Script interpreter host or untrusted process persistence
- Suspicious Microsoft Office add-in loaded
- Suspicious Microsoft Office template
- Suspicious Netsh Helper DLL execution
- Suspicious persistence via registry modification
- Suspicious port monitor loaded
- Suspicious print processor loaded
- Suspicious Startup shell folder modification
- Unusual file written in Startup folder
- Unusual process modified registry run key