A curated list of awesome malware persistence tools and resources.
-
Updated
Aug 25, 2026
A curated list of awesome malware persistence tools and resources.
Collection of malware persistence and hunting information. Be a persistent persistence hunter!
A complete hands-on reference of 67 Windows persistence techniques used by real-world APT groups. Each technique includes MITRE ATT&CK TTP mapping, known threat actor attribution, attack commands, verification steps, and cleanup — organized from No-Admin to Admin level. Built for red teamers, malware analysts, and cybersecurity learners.
Volatility plugin to search for all Autostart Extensibility Points (AESPs)
Autopsy plugin that scans the Auto-Start Extensibility Points (ASEPs) and list out the potential persistences
Windows malware techniques
Free Module 3: Advanced Android malware dropper demonstrating extreme persistence. Showcases silent APK payload installation via the PackageInstaller API, icon hiding, and background survival even after the host app is completely uninstalled
To associate your repository with the malware-persistence topic, visit your repo's landing page and select "manage topics."