Lightining fast, version 1.17.1 is already up and running both on #Github and #PowershellGallery, with enhanced detections for the techniques implemented in version 1.17.0. Thanks to @sixtyvividtails for the support and for pointing out how to further improve the tool!
Version 1.17.0 of #PersistenceSniper has just been uploaded on #Github and #PowershellGallery. This release sports 4 new detections, bringing the total number of detections to 60 🕵️
Version 1.16.3 of #PersistenceSniper is out. This includes a couple of bug fixes regarding the LSA Notify Package detections and the usage of the tool remotely. Make sure to update! Check it out at https://t.co/WFkCbKfW0e
Version 1.16.1 of #PersistenceSniper has been released. It fixes a bug in the fuction responsible of checking for the GhostTask technique which prevented its detection in certain situations.
https://t.co/WFkCbKfW0e
TIL: You can use undocumented CRYPT_STRING_BASE64URI flag in CryptBinaryToString() to make your Base64 string safe for URLs and filenames as defined in Section 5. of RFC4648.
#PersistenceSniper v1.16.0 is out! This release implements detections for the Boot Verification Program Hijacking and AppInit DLLs Injection techniques. Check the details at https://t.co/WFkCbKfW0e
If you don't run @PersistSniper as part of your threat hunting program, you're missing out on some really handy tooling. If you have a clean baseline, you can get just the diffs which can be very valuable intel.
https://t.co/yXlE3CUNFO
#PersistenceSniper version 1.15.1 is out! This release fixes a bug which would prevent certain persistences from showing up due to Powershell not being listed as a LOLBin in the LOLBas project, as pointed out by @Strassi7. Update right away!
https://t.co/WFkCbKfW0e
#PersistenceSniper has been downloaded almost 5500 times since it was released a bit more than a year ago! It looks like the project has been well received by the community so far 🦾
PersistenceSniper. PowerShell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines, by @last0x00
https://t.co/7ahoCgpMMo
#PersistenceSniper version 1.14.0 is out. This release implements a detection for the Directory Services Restore Mode (DSRM) backdoor that attackers can deploy on Domain Controllers.
https://t.co/WFkCbKfW0e
Finally, #PersistenceSniper gets a clear and complete Wiki for the project! It details how to deploy and use it, as well as some more "complex" usage examples and a detailed list of all the available detections with explanations. Check it here 👇
https://t.co/MxplVA4IaX