Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is persistence?

Persistence is a mechanism intended to maintain or regain access after the original route or session is interrupted. It may survive a restart, password reset, patch or loss of the original device.

Accounts, scheduled tasks, services, tokens, application consent, web shells, startup items and remote-management settings can all provide persistence.

Identify the mechanism and its trigger

Preserve the configuration, associated file or credential, target, trigger and identifiers. Establish when it was created, which account or process created it, the access it could provide and whether it remained after containment.

Creation and successful use are separate. A task may never run, a token may expire and a web shell may receive no command. Execution, authentication or connection evidence is needed to show that the mechanism actually restored or maintained access.

Do not infer persistence from continuity alone

Continuing activity may instead use a still-valid account, shared credential or legitimate service. Conversely, persistence can remain unused after the offender leaves. Test the actual route used on each return.

Creation timestamps can help sequence the incident but may reflect copying, system behaviour or manipulation. A foothold may also outlive its creator and be used later by someone else, so creation, use and personal attribution should remain distinct.

Key takeaway

Show what persistence mechanism existed, how it was created and whether it was used; neither its presence nor continuing access proves the other.

Reference: CIM-106Cyber Incidents & Offender Methods