Knowledge / detection IR

Persistence

Still there after reboot, password change, or the first cleanup. Scheduled tasks, tokens, and legitimate-looking remote access.

Persistence is how they stay: a service, a task, a login item, a mailbox rule, a cloud app grant, extra credentials. Reimaging one host does not revoke a stolen refresh token.

Hunt startup mechanisms, new admin, new OAuth apps, and remote-access tools you did not install. Cut identity persistence as well as host persistence, or they walk back in.

See also: Lateral movement, Incident response, Identity and access management, IR playbook.