PersistenceSniper is a digitally signed PowerShell module aimed at blue teams and incident responders for automated detection of persistence mechanisms on Windows systems. It implements detection logic for techniques listed in MITRE ATT&CK (e.g. registry run keys, scheduled tasks, service modifications) and is regularly updated with new detection paths.
Features
- Detects persistence across run keys, scheduled tasks, services, and WMI
- Aligns with MITRE ATT&CK persistence techniques
- Digitally signed and published via PowerShell Gallery
- Lightweight module (~3000 lines), no external dependencies
- Regular releases adding detection capabilities
- Suitable for automation and integration into SOAR workflows
Categories
SecurityLicense
MIT LicenseFollow PersistenceSniper
Other Useful Business Software
SoftCo: Enterprise Invoice and P2P Automation Software
SoftCo Accounts Payable Automation processes all PO and non-PO supplier invoices electronically from capture and matching through to invoice approval and query management. SoftCoAP delivers unparalleled touchless automation by embedding AI across matching, coding, routing, and exception handling to minimize the number of supplier invoices requiring manual intervention. The result is 89% processing savings, supported by a context-aware AI Assistant that helps users understand exceptions, answer questions, and take the right action faster.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of PersistenceSniper!