Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

All playbooks

Alert response · Persistence responders

Persistence established

Something arranged to run again later. The immediate risk is low; the risk of missing it is not.

Nothing is happening right now, and that is the point. Persistence is the part of a chain that survives your response.

What this does not establish

  • When it was installed. Registry and task timestamps are trivially set.
  • Whether it has ever run. Existence is not execution.
  • How it got there. Persistence is a consequence; the access is the incident.

0 of 9 ticked

Selected step

DetectStep 1 of 9

Identify the mechanism and what it launches

  • The payload path matters more than the autorun key.
  • A living-off-the-land binary in the command means the payload is elsewhere.
  • Copy the artefact before anything touches it.
  • Start the timeline now: every action, who took it, when.
  • Mailbox forwarding rules and new MFA devices are persistence too; check the identity plane.