persistence

term

security

An attacker's arrangements for surviving a reboot, a password change or a partial cleanup.

It is the difference between an incident that ends and one that returns, and it is why containment is judged by whether the intruder can come back rather than by whether the current session is closed. The mechanisms are almost always legitimate features - scheduled tasks, startup entries, service accounts, mail rules, added credentials on an identity provider - which is why hunting for persistence is a review of configuration rather than a search for files, and why an organisation that reimages a host without auditing identity often finds the visitor already waiting.

Also known as: foothold

All glossary entries