What is persistence in a cloud account?¶
Persistence is a method that allows continued or renewed access to a cloud account after the original access route is removed.
Evidential caution: that changing the password removes every foothold.
What this means¶
Persistence may include new administrator accounts, delegated access, application consent, mailbox rules, recovery changes, trusted devices, API keys, service accounts or long-lived tokens.
An attacker may also create forwarding, sharing or automation rules that continue operating without an active interactive session.
But several unexpected persistence mechanisms created after suspicious access are highly relevant.
Containment should address each access route, not just the password.
Persistence may also exist outside the main account, such as a linked identity provider, delegated tenant or external automation platform. The review should follow the access chain rather than stopping at one service.
Where persistence is removed, record the pre-removal state, the exact control used and any later activity. This helps establish whether the foothold was active and whether containment succeeded.
What to check or do next¶
- Investigators should identify new or changed permissions, roles, applications, keys, rules and recovery methods.
- Check when each was created, by which account or session and whether it remains active.
- Compare the changes with administrator audit logs, application-consent records, token events and expected organisational activity.
- Preserve the configuration and audit records before removal where operationally possible.
Evidential limits¶
Do not assume unfamiliar configuration is malicious. Some changes may be legitimate administration or automation.
Operational takeaway
Cloud persistence allows access or data flow to continue after the original login is secured, so examine roles, tokens, applications, rules and recovery settings for hidden footholds.