A PowerShell module for Blue Teams, Incident Responders, and System Administrators to hunt persistence techniques implanted in Windows machines.
PersistenceSniper is a PowerShell module that hunts for persistence techniques implanted by attackers on Windows machines. It automates the detection of over 60 known persistence methods, helping security professionals identify and analyze malicious footholds during incident response. The tool is designed for remote execution and automated result parsing across multiple systems.
Blue Teams, Incident Responders, and System Administrators who need to detect and analyze persistence mechanisms on Windows environments, especially in scalable or remote scenarios.
Developers choose PersistenceSniper for its specialized focus on persistence hunting, remote execution capabilities, and coverage of techniques not always included in other tools like Sysinternals Autoruns, all within an actively maintained PowerShell module.
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Detects over 60 persistence techniques, including some not covered by Sysinternals Autoruns, providing broader detection capabilities for security professionals.
Can be run remotely across multiple Windows machines without complex setup, enabling rapid analysis and comparison in enterprise environments.
Parses and compares results automatically, streamlining incident response workflows as highlighted in the README's focus on automation.
Digitally signed with a valid code signing certificate, ensuring authenticity and reducing the risk of tampering or malicious use.
Regularly updated with new releases and persistence technique implementations, keeping the tool current with evolving threats.
Limited to Windows environments and requires PowerShell, making it unsuitable for cross-platform investigations or teams unfamiliar with PowerShell.
Licensed under a non-commercial clause, which prohibits commercial use without permission, limiting deployment in business settings.
Focused on post-hoc hunting and analysis, lacking built-in capabilities for real-time detection or alerting, which may require additional tools.
As admitted in the README, it's not ideal for users who need a GUI-based tool like Autoruns for easy, visual inspection and interaction.
PersistenceSniper is an open-source alternative to the following products: