hunting-for-persistence-mechanisms-in-windows
mukul975/Anthropic-Cybersecurity-Skills
This comprehensive guide outlines a structured methodology for threat hunting and incident response, focusing on identifying adversary persistence mechanisms across Windows endpoints. It covers critical areas such as Registry Run/RunOnce keys, services, scheduled tasks, WMI event subscriptions, and COM hijacking. Use this workflow to proactively detect unauthorized backdoors, strengthen detection rules, and assess overall security posture against MITRE ATT&CK techniques (T1547).