persistence_scan
Detect malware persistence mechanisms including LaunchAgents, systemd units, cron jobs, and shell profile injections. Flags high-risk patterns to identify compromise.
Instructions
Scan this machine for malware persistence mechanisms: LaunchAgents/LaunchDaemons (macOS), systemd units (Linux), cron jobs, and shell profile injections. Flags high-risk patterns like curl-pipe-to-bash, base64-encoded payloads, and binaries executing from /tmp. Essential first step when investigating a potentially compromised machine.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||