TA0003

Persistence Detection Rules

The adversary is trying to maintain their foothold. Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.

df00tech ships 225 production-ready detection rules mapped to the Persistence tactic (TA0003). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.

Unlock the full Pro package

Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.

Upgrade to Pro

Persistence detections (225)

Related tactics

All MITRE ATT&CK Tactics