Advanced Persistence
Course Description
Learn advanced persistence techniques used by sophisticated threat actors to maintain long-term access.
Course Structure
Modules
Module 1: Persistence Fundamentals (5h)
- Persistence concepts
- MITRE ATT&CK mapping
- Cleanup importance
- Detection surfaces
Module 2: User-Land Persistence (6h)
- Registry persistence
- Scheduled tasks
- Services
- COM hijacking
- DLL search order
Module 3: Kernel Persistence (8h)
- Driver loading
- Callback registration
- Kernel hooks
- Filter drivers
Module 4: Firmware Persistence (6h)
- UEFI basics
- Bootkit concepts
- Firmware implants
- BMC attacks
Module 5: Rootkits (7h)
- User-mode rootkits
- Kernel rootkits
- Hypervisor rootkits
- Hiding techniques
Module 6: Cloud Persistence (5h)
- IAM backdoors
- Lambda persistence
- Container persistence
- Cross-account access
Module 7: Active Directory (4h)
- Golden tickets
- Skeleton key
- AdminSDHolder
- DCShadow
Module 8: Detection Evasion (4h)
- Anti-forensics
- Log manipulation
- Timestomping
- Artifact removal
Tools
| Tool | Purpose |
|---|---|
| Mimikatz | Credential/tickets |
| DSInternals | AD persistence |
| KDU | Driver loading |
| Volatility | Detection |
📄️ Overview
Persistence techniques: rootkits, bootkits, and advanced implants