All playbooks
Alert response · Persistence responders
Persistence established
Something arranged to run again later. The immediate risk is low; the risk of missing it is not.
Nothing is happening right now, and that is the point. Persistence is the part of a chain that survives your response.
What this does not establish
- When it was installed. Registry and task timestamps are trivially set.
- Whether it has ever run. Existence is not execution.
- How it got there. Persistence is a consequence; the access is the incident.
0 of 9 ticked
Selected step
DetectStep 1 of 9
Identify the mechanism and what it launches
- The payload path matters more than the autorun key.
- A living-off-the-land binary in the command means the payload is elsewhere.
- Copy the artefact before anything touches it.
- Start the timeline now: every action, who took it, when.
- Mailbox forwarding rules and new MFA devices are persistence too; check the identity plane.