Category: Forensics
Description: Q10. we think that the malware uses persistence technique can you detect it ?
example : crew{Schedule_Task}
Author : 0xSh3rl0ck
Files: No files.
Tags: No tags.
TA0003
Windows Service
T1543.003
Stop service
Start service
Registry Run Keys / Startup Folder
T1547.001
Persist via Run registry key
Winlogon Helper DLL
T1547.004
Persist via Winlogon Helper DLL registry key