Persistence Detection Rules
The adversary is trying to maintain their foothold. Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.
df00tech ships 225 production-ready detection rules mapped to the Persistence tactic (TA0003). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Persistence detections (225)
- CVE-2012-1854 CVE-2012-1854 - Microsoft VBA Insecure Library Loading (DLL Hijacking)
- CVE-2017-7921 Hikvision Improper Authentication Exploitation (CVE-2017-7921)
- CVE-2021-26828 CVE-2021-26828: OpenPLC ScadaBR Unrestricted File Upload RCE
- CVE-2022-48503 CVE-2022-48503 Apple Multiple Products Unspecified Vulnerability Exploitation
- CVE-2023-27351 CVE-2023-27351 - PaperCut NG/MF Improper Authentication Exploitation
- CVE-2023-41974 Apple iOS/iPadOS Use-After-Free Exploitation (CVE-2023-41974)
- CVE-2024-3400 Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)
- CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal and Arbitrary File Upload
- CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted File Upload (CVE-2024-7694)
- CVE-2024-21887 Ivanti Connect Secure Authenticated Command Injection (CVE-2024-21887)
- CVE-2024-26234 CVE-2024-26234 — Windows Proxy Driver Spoofing via Malicious Signed Driver
- CVE-2025-2746 CVE-2025-2746: Kentico Xperience CMS Authentication Bypass
- CVE-2025-2749 Kentico Xperience Path Traversal and Arbitrary File Upload (CVE-2025-2749)
- CVE-2025-6218 CVE-2025-6218: RARLAB WinRAR Path Traversal Exploitation
- CVE-2025-11953 React Native Community CLI OS Command Injection (CVE-2025-11953)
- CVE-2025-12480 Gladinet Triofox Improper Access Control Exploitation Detected
- CVE-2025-14611 Gladinet CentreStack and Triofox Hard-Coded Cryptographic Key Exploitation
- CVE-2025-15556 Notepad++ Download of Code Without Integrity Check (CVE-2025-15556)
- CVE-2025-21589 Juniper Session Smart Router Authentication Bypass (CVE-2025-21589)
- CVE-2025-24893 CVE-2025-24893 XWiki Platform Eval Injection Exploitation
- CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data (CVE-2025-26399)
- CVE-2025-32432 CVE-2025-32432: Craft CMS Remote Code Injection
- CVE-2025-32975 Quest KACE SMA Improper Authentication Exploitation Detected
- CVE-2025-40551 CVE-2025-40551 — SolarWinds Web Help Desk Deserialization RCE
- CVE-2025-41244 CVE-2025-41244 - VMware Aria Operations & VMware Tools Privilege Escalation via Unsafe Actions
- CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability (CVE-2025-43510)
- CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Exploitation (CVE-2025-43520)
- CVE-2025-48703 CVE-2025-48703 - CWP Control Web Panel OS Command Injection
- CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data (CVE-2025-49113)
- CVE-2025-52691 SmarterMail Unrestricted File Upload Exploitation (CVE-2025-52691)
- CVE-2025-54068 Laravel Livewire Code Injection (CVE-2025-54068)
- CVE-2025-54236 Adobe Commerce / Magento Improper Input Validation (CVE-2025-54236)
- CVE-2025-54313 Prettier eslint-config-prettier Embedded Malicious Code (CVE-2025-54313)
- CVE-2025-55182 CVE-2025-55182 — Meta React Server Components Remote Code Execution
- CVE-2025-58034 Fortinet FortiWeb OS Command Injection (CVE-2025-58034)
- CVE-2025-58048 CVE-2025-58048: Paymenter Remote Code Execution via Unrestricted File Upload
- CVE-2025-59374 ASUS Live Update Embedded Malicious Code (CVE-2025-59374)
- CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature (CVE-2025-59718)
- CVE-2025-60710 Microsoft Windows Link Following Vulnerability (CVE-2025-60710)
- CVE-2025-64328 Sangoma FreePBX OS Command Injection (CVE-2025-64328)
- CVE-2025-68645 Synacor Zimbra Collaboration Suite PHP Remote File Inclusion (CVE-2025-68645)
- CVE-2026-1281 CVE-2026-1281 — Ivanti EPMM Code Injection Exploitation
- CVE-2026-1603 Ivanti Endpoint Manager (EPM) Authentication Bypass (CVE-2026-1603)
- CVE-2026-3502 TrueConf Client Download of Code Without Integrity Check (CVE-2026-3502)
- CVE-2026-6973 CVE-2026-6973: Ivanti EPMM Improper Input Validation Exploitation
- CVE-2026-7473 Arista EOS Incomplete Comparison Authentication Bypass (CVE-2026-7473)
- CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code (CVE-2026-8398)
- CVE-2026-10520 Ivanti Sentry OS Command Injection Exploitation (CVE-2026-10520)
- CVE-2026-15410 SonicWall SMA1000 Code Injection Exploitation (CVE-2026-15410)
- CVE-2026-20045 CVE-2026-20045: Cisco Unified Communications Manager Code Injection
- CVE-2026-20127 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass (CVE-2026-20127)
- CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format (CVE-2026-20128)
- CVE-2026-20253 CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function
- CVE-2026-20963 Microsoft SharePoint Deserialization of Untrusted Data (CVE-2026-20963)
- CVE-2026-21533 Microsoft Windows Improper Privilege Management (CVE-2026-21533)
- CVE-2026-22719 CVE-2026-22719: VMware Aria Operations Command Injection
- CVE-2026-24423 SmarterMail Missing Authentication for Critical Function (CVE-2026-24423)
- CVE-2026-24858 Fortinet Multiple Products Authentication Bypass via Alternate Path or Channel (CVE-2026-24858)
- CVE-2026-30120 Remotion RCE via Code Injection (CVE-2026-30120)
- CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres (CVE-2026-31431)
- CVE-2026-33634 Aquasecurity Trivy Embedded Malicious Code (CVE-2026-33634)
- CVE-2026-33646 CVE-2026-33646: Mise Arbitrary Code Execution via Tera Template Injection in .tool-versions
- CVE-2026-33825 CVE-2026-33825 - Microsoft Defender Insufficient Access Control Exploitation
- CVE-2026-34197 Apache ActiveMQ Improper Input Validation (CVE-2026-34197)
- CVE-2026-35616 CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Exploitation
- CVE-2026-41940 CVE-2026-41940: WebPros cPanel & WHM / WP2 Missing Authentication for Critical Function
- CVE-2026-42271 BerriAI LiteLLM Command Injection (CVE-2026-42271)
- CVE-2026-44179 CVE-2026-44179: XWiki Pro Macros RCE via Excerpt-Include Macro
- CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization RCE (CVE-2026-45247)
- CVE-2026-45659 CVE-2026-45659 Microsoft SharePoint Server Deserialization RCE
- CVE-2026-46595 CVE-2026-46595: golang.org/x/crypto/ssh VerifiedPublicKeyCallback Authentication Bypass
- CVE-2026-47103 python-statemachine SCXML <data expr> Eval Injection (CVE-2026-47103)
- CVE-2026-47396 PraisonAI Call Server Unauthenticated Agent Access (CVE-2026-47396)
- CVE-2026-47413 CVE-2026-47413: PraisonAI Platform Unauthorized Workspace Owner Privilege Escalation
- CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE via JSON Script Runner
- CVE-2026-47724 nebula-mesh API Ownership Check Bypass — Cross-Operator Privilege Escalation
- CVE-2026-47744 Shopper Framework Authorization Bypass and RBAC Privilege Escalation in Team Settings
- CVE-2026-48027 Nx Console Embedded Malicious Code Execution (CVE-2026-48027)
- CVE-2026-48030 Pheditor OS Command Injection via Unsanitized 'dir' Parameter (CVE-2026-48030)
- CVE-2026-48062 CVE-2026-48062: CodeIgniter4 File Upload Extension Validation Bypass (ext_in Rule)
- CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-48172)
- CVE-2026-48558 CVE-2026-48558 — SimpleHelp Authentication Bypass (CWE-347)
- CVE-2026-48749 CVE-2026-48749: Incus Arbitrary File Read/Write via rootfs Symlink in Malicious Image
- CVE-2026-48753 CVE-2026-48753: Incus S3 Multipart Upload Path Traversal Arbitrary File Write
- CVE-2026-48769 CVE-2026-48769: Incus Arbitrary File Write via Trusted Image Hash
- CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control (CVE-2026-48907)
- CVE-2026-48908 CVE-2026-48908 - JoomShaper SP Page Builder Unrestricted File Upload
- CVE-2026-50545 CVE-2026-50545: Fission Environment CRD PodSpec Injection
- CVE-2026-52806 CVE-2026-52806: Gogs RCE via git rebase --exec Argument Injection in PR Merge
- CVE-2026-52813 Gogs Path Traversal in Organization Name Leading to RCE via Git Hooks
- CVE-2026-52831 Nuclio Cron Trigger Header/Body Command Injection (CVE-2026-52831)
- CVE-2026-53633 CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite
- CVE-2026-54051 CVE-2026-54051: network-ai npm Package OS Command Injection
- CVE-2026-54159 PrestaShop ps_facetedsearch PHP Object Injection Leading to Unauthenticated RCE (CVE-2026-54159)
- CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Exploitation (CVE-2026-58644)
- T1034 Path Interception
- T1037 Boot or Logon Initialization Scripts
- T1037.001 Logon Script (Windows)
- T1037.002 Login Hook
- T1037.003 Network Logon Script
- T1037.004 RC Scripts
- T1037.005 Startup Items
- T1053 Scheduled Task/Job
- T1053.002 At
- T1053.003 Cron
- T1053.005 Scheduled Task
- T1053.006 Systemd Timers
- T1053.007 Container Orchestration Job
- T1062 Hypervisor
- T1078 Valid Accounts
- T1078.001 Default Accounts
- T1078.002 Domain Accounts
- T1078.003 Local Accounts
- T1078.004 Cloud Accounts
- T1098 Account Manipulation
- T1098.001 Additional Cloud Credentials
- T1098.002 Additional Email Delegate Permissions
- T1098.003 Additional Cloud Roles
- T1098.004 SSH Authorized Keys
- T1098.005 Device Registration
- T1098.006 Additional Container Cluster Roles
- T1098.007 Additional Local or Domain Groups
- T1108 Redundant Access
- T1112 Modify Registry
- T1133 External Remote Services
- T1136 Create Account
- T1136.001 Local Account
- T1136.002 Domain Account
- T1136.003 Cloud Account
- T1137 Office Application Startup
- T1137.001 Office Template Macros
- T1137.002 Office Test
- T1137.003 Outlook Forms
- T1137.004 Outlook Home Page
- T1137.005 Outlook Rules
- T1137.006 Add-ins
- T1176 Software Extensions
- T1176.001 Browser Extensions
- T1176.002 IDE Extensions
- T1197 BITS Jobs
- T1205 Traffic Signaling
- T1205.001 Port Knocking
- T1205.002 Socket Filters
- T1505 Server Software Component
- T1505.001 SQL Stored Procedures
- T1505.002 Transport Agent
- T1505.003 Web Shell
- T1505.004 IIS Components
- T1505.005 Terminal Services DLL
- T1505.006 vSphere Installation Bundles
- T1525 Implant Internal Image
- T1542 Pre-OS Boot
- T1542.001 System Firmware
- T1542.002 Component Firmware
- T1542.003 Bootkit
- T1542.004 ROMMONkit
- T1542.005 TFTP Boot
- T1543 Create or Modify System Process
- T1543.001 Launch Agent
- T1543.002 Systemd Service
- T1543.003 Windows Service
- T1543.004 Launch Daemon
- T1543.005 Container Service
- T1546 Event Triggered Execution
- T1546.001 Change Default File Association
- T1546.002 Screensaver
- T1546.003 Windows Management Instrumentation Event Subscription
- T1546.004 Unix Shell Configuration Modification
- T1546.005 Trap
- T1546.006 LC_LOAD_DYLIB Addition
- T1546.007 Netsh Helper DLL
- T1546.008 Accessibility Features
- T1546.009 AppCert DLLs
- T1546.010 AppInit DLLs
- T1546.011 Application Shimming
- T1546.012 Image File Execution Options Injection
- T1546.013 PowerShell Profile
- T1546.014 Emond
- T1546.015 Component Object Model Hijacking
- T1546.016 Installer Packages
- T1546.017 Udev Rules
- T1546.018 Python Startup Hooks
- T1547 Boot or Logon Autostart Execution
- T1547.001 Registry Run Keys / Startup Folder
- T1547.002 Authentication Package
- T1547.003 Time Providers
- T1547.004 Winlogon Helper DLL
- T1547.005 Security Support Provider
- T1547.006 Kernel Modules and Extensions
- T1547.007 Re-opened Applications
- T1547.008 LSASS Driver
- T1547.009 Shortcut Modification
- T1547.010 Port Monitors
- T1547.012 Print Processors
- T1547.013 XDG Autostart Entries
- T1547.014 Active Setup
- T1547.015 Login Items
- T1554 Compromise Host Software Binary
- T1556 Modify Authentication Process
- T1556.001 Domain Controller Authentication
- T1556.002 Password Filter DLL
- T1556.003 Pluggable Authentication Modules
- T1556.004 Network Device Authentication
- T1556.005 Reversible Encryption
- T1556.006 Multi-Factor Authentication
- T1556.007 Hybrid Identity
- T1556.008 Network Provider DLL
- T1556.009 Conditional Access Policies
- T1574 Hijack Execution Flow
- T1574.001 DLL
- T1574.002 DLL Side-Loading
- T1574.004 Dylib Hijacking
- T1574.005 Executable Installer File Permissions Weakness
- T1574.006 Dynamic Linker Hijacking
- T1574.007 Path Interception by PATH Environment Variable
- T1574.008 Path Interception by Search Order Hijacking
- T1574.009 Path Interception by Unquoted Path
- T1574.010 Services File Permissions Weakness
- T1574.011 Services Registry Permissions Weakness
- T1574.012 COR_PROFILER
- T1574.013 KernelCallbackTable
- T1574.014 AppDomainManager
- T1653 Power Settings
- T1668 Exclusive Control
- T1671 Cloud Application Integration
Related tactics
266 detections
222 detections