Persistence at Play: You Can't Evict What You Can't See

Eleven persistence techniques, one unified detection framework: how to hunt what's hiding in your environment before it executes.
Details
About this event
Who Should Attend
- SOC Analysts
- Threat Hunters
- Detection Engineers
- Incident Responders
- Security Engineers
- Blue Team Professionals
- Security Operations Leaders
Why Should You Attend
- Understand why persistence, not initial access, is the biggest challenge in modern threat detection.
- Learn the eleven persistence techniques attackers use to maintain access and how to detect each one.
- Discover a unified detection framework that simplifies persistence hunting across your environment.
- Explore real-world attack scenarios that demonstrate how threats can be identified at the persistence stage before payload execution.
- Gain practical guidance to operationalize persistence hunting with actionable configuration changes and detection rules.
- Leave with strategies you can immediately apply to improve your SOC's detection coverage and response.
Agenda
- Opening Remarks & Webinar Overview
- Setting the context for persistence-focused threat detection.
- Why organizations need to hunt persistence as a continuous state, not a single event.
- Session 1: The Persistence Problem
- Why dwell time is a persistence hunting failure, not an initial access failure.
- Understanding the gap between compromise and detection.
- Session 2: Eleven Persistence Technique Tiers
- From Run Keys to AppDomainManager Injection.
- Understanding attacker persistence mechanisms and the detection opportunities for each technique.
- Session 3: The Detection Framework
- Building a unified sweep query.
- Identifying detection coverage gaps.
- Creating scalable behavioral detection strategies.
- Session 4: Persistence Hunting in Action
- Four real-world attack scenarios.
- Detecting adversaries at the persistence stage rather than after payload execution.
- Session 5: Operationalizing Persistence Hunting
- Three configuration changes to improve visibility.
- Eight practical detection rules.
- Immediate actions to strengthen SOC readiness.
- Live Q&A
- Interactive discussion with the speakers.
- Answers to attendee questions and implementation challenges.
Recap
This session walked through eleven persistence techniques attackers use to maintain access after initial compromise, from Run Key modifications to AppDomainManager injection, and the detection opportunities each one creates. The team introduced a unified sweep query for surfacing persistence coverage gaps across an environment, then worked through four real-world attack scenarios showing how defenders can catch adversaries at the persistence stage rather than after payload execution. The session closed with three configuration changes and eight practical detection rules attendees can apply directly to strengthen SOC readiness, followed by live Q&A.
Recording (register to access)
The recording and slides from this session are available on request.
Share your details and we will unlock them here and email you a copy.