Medium severityHARDEC6 steps · 6 phases
Persistence Eradication
Systematic removal of attacker persistence mechanisms (service, task, registry run-key, WMI, startup).
Information note
Informational note: In persistence cleanup, systematically scan all common vectors: registry run keys (T1547.001), scheduled tasks (T1053), WMI event subscriptions (T1546.003), and services (T1543.003). Removing a single persistence mechanism may overlook the fact that the attacker may have installed multiple backup backdoors. Ensure network isolation and acquire forensic images before comprehensively investigating all systems.
1
Preparation
1 steps- Baseline & autoruns visibility
Known-good configuration, Sysmon, autoruns/scheduled task inventory.
2
Identification
1 steps- List all persistence
Services, scheduled tasks, run-keys, WMI event subscriptions, startup folders, OAuth grants.
3
Containment
1 steps- Stop re-activation
Isolate affected hosts, lock accounts hosting persistence.
4
Eradication
1 steps- Remove all simultaneously