Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
EU Fines Google Record DMA Sum for Search Self- Finalizes Against
May 26, 2026
Phishing Bypasses SMS Security via RCS and i Services Traditional
May 26, 2026
PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt
May 26, 2026
Home/CyberSecurity News/PyrsistenceSniper – Tool that Detects 117 Persistence Malware
CyberSecurity News

PyrsistenceSniper – Tool that Detects 117 Persistence Malware

PyrsistenceSniper, an advanced new tool, empowers cybersecurity analysts to detect offline persistence across Windows, Linux, and macOS. It identifies 117 distinct persistence mechanisms. Originally...

Emy Elsamnoudy
Emy Elsamnoudy
May 24, 2026 3 Min Read
14 0

PyrsistenceSniper, an advanced new tool, empowers cybersecurity analysts to detect offline persistence across Windows, Linux, and macOS. It identifies 117 distinct persistence mechanisms.

Originally inspired by Autoruns and PersistenceSniper, this Python-based solution developed by Hexastrike enables rapid triage of forensic collections without requiring live system access.

According to the Hexastrike GitHub repository, PyrsistenceSniper runs directly against mounted disk images, Velociraptor collections, and KAPE dumps. The tool utilizes the libregf library to parse registry hives natively, allowing it to complete comprehensive scans of heavily used systems in under thirty seconds.

Analysts from Hexastrike explain that investigators can leverage signature-based filtering to validate Authenticode signatures and separate actual malicious persistence from default operating system noise.

PyrsistenceSniper Detects 117 Persistence Techniques

The command-line interface provides detailed terminal output that visually flags anomalies based on recognized MITRE ATT&CK techniques.

PyrsistenceSniper Detects 117 Persistence Techniques
Tool Usage

Security researchers report that PyrsistenceSniper supports standalone artifact scanning for isolated files like NTUSER.DAT or the SYSTEM hive, which is particularly useful when full directory structures are unavailable

Maurice Fielenbach notes that each finding is automatically enriched with file existence checks, SHA-256 hashes, and known LOLBin classifications to streamline the incident response process.

Cybersecurity professionals can deploy YAML-based detection profiles to customize allow and block rules either globally or per individual check.

Hexastrike documentation explains that this system prioritizes block rules, automatically categorizing matches as high severity while filtering out known-good entities like Microsoft-signed binaries.

Threat hunters emphasize that this targeted suppression mechanism eliminates redundant alerts, often reducing total output volume by up to ninety percent during forensic analysis.

Hexastrike aligned the tool’s unique persistence checks directly with nine distinct MITRE ATT&CK techniques to ensure standardized threat reporting.

Security teams utilize these categorizations to track mechanisms ranging from hijacked execution flows to modified authentication processes across compromised environments. The following table illustrates a cross-section of the specific persistence techniques identified by PyrsistenceSniper.

MITRE Technique ID Technique Category Notable Checks
T1037 Boot and Logon Initialization Group Policy scripts, Logon scripts
T1053 Scheduled Task/Job Ghost tasks, Scheduled task files
T1543 System Process Modification Service failure commands, Windows service DLLs
T1546 Event Triggered Execution WMI event subscriptions, Accessibility tools
T1547 Boot/Logon Autostart Run keys, Startup folders, Print monitors

Forensic investigators can export PyrsistenceSniper findings into various formats, including console, CSV, HTML, and XLSX, to integrate seamlessly with existing analysis workflows.

Recent updates, highlighted by Maurice Fielenbach, introduced interactive HTML reports that allow defenders to dynamically filter and sort severity ratings.

Incident response teams frequently use the CSV and XLSX outputs to stack anomalous indicators across multiple compromised systems simultaneously.

Security engineers can install PyrsistenceSniper directly from the Python Package Index using standard package managers or by compiling it from the official source code.

The development team also provides an official Docker container, which allows analysts to scan triage collections without configuring local Python environments or system dependencies. Digital forensics professionals frequently utilize this containerized approach to export full HTML reports and CSV files dynamically during active incident response engagements.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CybersecurityMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Patch Nginx Poolslip Vulnerability: DoS Nginx-poolslip Enables

Next Post

Top 10 Malware Sandbox Tools for Security Teams in

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Anthropic’s Restricted Claude Nears Public Release via Code
May 26, 2026
Cloud Atlas APT Modifies termsrv.dll for Group Enable
May 25, 2026
InvisibleFerret Malware Evades Detection with .pyd
May 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Sarah simpson
Sarah simpson
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us