Skip to content

Releases: last-byte/PersistenceSniper

PersistenceSniper v1.16.0

31 Mar 19:47
Compare
Choose a tag to compare

This release implements detections for 2 new persistence techniques (Boot Verification Program Hijacking and App Init DLLs Injection) as well as fix a false positive in the Suborner Attack as reported by @strassi.

PersistenceSniper v1.15.1

15 Feb 16:14
Compare
Choose a tag to compare

This release fixes a gap in the detection of persistences relying on Powershell. The bug was in the Get-IfSafeExecutable function, which calls Get-IfLolbin function, which in turn does not list Powershell.exe as a LOLBin.

PersistenceSniper v1.15.0

09 Jan 19:07
Compare
Choose a tag to compare

This release implements detections for the GhostTask technique.

PersistenceSniper v1.14.0

04 Nov 18:43
Compare
Choose a tag to compare

This release implements a detection for the DSRM backdoor in Domain Controllers, as well as a bug in the Parse-NetUser internal function.

PersistenceSniper v1.13.0

05 Oct 22:19
Compare
Choose a tag to compare

This release implements detection for RID hijacking and the Suborner attack.

PersistenceSniper v1.12.1

12 Aug 13:20
Compare
Choose a tag to compare

This release implements a fix for the Accessibility Tools persistence detection which, up to 1.12.0, did not look for Utilman.exe hijacking.

PersistenceSniper v1.12.0

22 May 17:03
Compare
Choose a tag to compare

This release fixes a bug in the OutputCSV parameter, which up to version 1.11.0 would included false positives filtered out by the DiffCSV parameter, as well as implementing support for logging the output of the tool to the Windows Event Log, thanks to Antonio Blescia.

PersistenceSniper v1.11.0

05 May 14:52
Compare
Choose a tag to compare

This release fixes a bug in the CmdAutoRun detection and adds three new detections. Check CHANGELOG.

PersistenceSniper v1.10.1

04 May 18:44
5b56b21
Compare
Choose a tag to compare

This release fixes a bug in the DiffCSV parameter.

PersistenceSniper v1.9.3

18 Apr 08:02
0bec863
Compare
Choose a tag to compare

This release adds support for checking artefacts against Virustotal through its APIs (you need a valid API key) using the -VTApiKey parameter and implements detections for malicious Office templates.