Persistence is the set of techniques attackers use to keep access to a compromised system across reboots, logouts, password changes and other interruptions that would otherwise cut them off.
How persistence works
Malware or an intruder rarely wants to break in twice. After the initial compromise, they configure something that will start their code again automatically. In the MITRE ATT&CK framework, Persistence is a separate tactic (TA0003) with dozens of techniques. Common examples:
- Autostart entries – Run keys in the Windows Registry or the Startup folder (T1547.001).
- Scheduled tasks and services – Windows Task Scheduler, new or modified services, cron jobs and systemd units on Linux, LaunchAgents on macOS.
- WMI event subscriptions – code that runs when a system event occurs (T1546.003).
- Account-based persistence – creating new accounts, adding SSH keys or registering extra MFA devices and OAuth apps in cloud environments.
- Server-side implants – web shells on web servers and modified firmware on edge devices.
- Boot-level persistence – bootkits and UEFI implants that survive even a reinstall of the operating system.
Why persistence matters
Persistence turns a short-lived intrusion into long-term access, giving attackers time for reconnaissance, data theft and ransomware deployment. Advanced groups set up several independent mechanisms so that removing one does not evict them. Incomplete cleanup is a common reason why victims are compromised again shortly after an incident.
How to detect and remove persistence
- Monitor creation of services, scheduled tasks, Run keys and WMI subscriptions with EDR or Sysmon.
- Regularly audit autostart locations with tools such as Microsoft Autoruns.
- Review cloud accounts for new users, keys, OAuth grants and MFA methods.
- During incident response, map all mechanisms before eviction, then rotate credentials and, if in doubt, rebuild.