PersistenceSniper is a digitally signed PowerShell module aimed at blue teams and incident responders for automated detection of persistence mechanisms on Windows systems. It implements detection logic for techniques listed in MITRE ATT&CK (e.g. registry run keys, scheduled tasks, service modifications) and is regularly updated with new detection paths.
Features
- Detects persistence across run keys, scheduled tasks, services, and WMI
- Aligns with MITRE ATT&CK persistence techniques
- Digitally signed and published via PowerShell Gallery
- Lightweight module (~3000 lines), no external dependencies
- Regular releases adding detection capabilities
- Suitable for automation and integration into SOAR workflows
Categories
SecurityLicense
MIT LicenseFollow PersistenceSniper
Other Useful Business Software
Effortlessly Manage Product Information
A single source of truth for all of your product information with easy ways to distribute that data to wherever it needs to go, including the most powerful e-commerce connectors in the industry.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of PersistenceSniper!