Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Does the presence of persistence prove it was used?

No. Creating a persistence mechanism, having the capability to use it and actually using it are separate events.

A task may never trigger, a service may fail, a token may expire, an account may never authenticate and a web shell may receive no command.

Look for the use event

Match the mechanism to the record its operation should create: task or service history, process execution, authentication, API calls, web requests, network connections and resulting file or account actions.

State the finding precisely. The account existed is different from the account authenticated; the task was created is different from the task ran successfully.

Explain what absence can support

No use record is not always proof of no use. Logging may have been disabled, records may have expired or activity may have occurred in a source not collected. Assess expected coverage and retention before interpreting silence.

An unused mechanism may still support an inference of preparation or capability, particularly where its timing and concealment connect it to the incident. That inference must not be converted into proof of continued access. Preserve the distinction in conclusions and timelines.

Key takeaway

Prove persistence creation and use separately; where execution cannot be shown, describe capability or preparation at the level the evidence supports.

Reference: CIM-117Cyber Incidents & Offender Methods