{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:03:23Z","timestamp":1780589003912,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":92,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Dutch Ministry of Economic Affairs and Climate Policy (EZK)","award":["AVR project \u201cFirmPatch\u201d"],"award-info":[{"award-number":["AVR project \u201cFirmPatch\u201d"]}]},{"name":"French National Research Agency (ANR)","award":["ANR-22-PECY-0007 (DefMal)"],"award-info":[{"award-number":["ANR-22-PECY-0007 (DefMal)"]}]},{"name":"German Federal Ministry for Economic Affairs and Energy (BMWE)","award":["03EI4101D (TRACEY)"],"award-info":[{"award-number":["03EI4101D (TRACEY)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3805971","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1371-1386","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["SoK: Systematization, Detection, and Hunting of Windows Malware Persistence Techniques"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-1870-2860","authenticated-orcid":false,"given":"Jorik","family":"van Nielen","sequence":"first","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7820-1927","authenticated-orcid":false,"given":"Andrea","family":"Oliveri","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0138-0861","authenticated-orcid":false,"given":"Jerre","family":"Starink","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2929-5001","authenticated-orcid":false,"given":"Andreas","family":"Peter","sequence":"additional","affiliation":[{"name":"University of Oldenburg, Oldenburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4467-072X","authenticated-orcid":false,"given":"Marieke","family":"Huisman","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9547-3502","authenticated-orcid":false,"given":"Simone","family":"Aonzo","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5957-6213","authenticated-orcid":false,"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0329-1830","authenticated-orcid":false,"given":"Andrea","family":"Continella","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2014. FuzzySecurity Windows Userland Persistence Fundamentals. https:\/\/fuzzysecurity.com\/tutorials\/19.html."},{"key":"e_1_3_2_1_2_1","unstructured":"2018. Eideon blog. https:\/\/www.eideon.com\/."},{"key":"e_1_3_2_1_3_1","unstructured":"2019. Defensive and offensive security in a nutshell. https:\/\/giuliocomi.blogspot.com\/."},{"key":"e_1_3_2_1_4_1","unstructured":"2019. Persistence Tactic j MITRE ATT&CK. https:\/\/attack.rnitre.org\/tactics\/TA0003\/."},{"key":"e_1_3_2_1_5_1","unstructured":"MDSec 2019. Persistence: \u201cThe Continued or Prolonged Existence of Something\u201d: Part 3 - WMI Event Subscription. MDSec. https:\/\/www.mdsec.co.uk\/2019\/05\/persistence-the-continued-or-prolonged-existence-of-something-part-3-wmi-event-subscription\/."},{"key":"e_1_3_2_1_6_1","unstructured":"2020. AV-TEST Security Report 2019-2020. https:\/\/www.av-test.org\/fileadmin\/pdf \/ security_report\/AV-TEST_Security_Report_2019-2020.pdf."},{"key":"e_1_3_2_1_7_1","unstructured":"2023. 2023 Cyberthreat Defense Report. https:\/\/cyberedgegroup.com\/resources\/2023-cyberthreat-defense-report\/."},{"key":"e_1_3_2_1_8_1","unstructured":"Mandiant 2023. Back in a Bit: Attacker Use of the Windows Background Intelligent Transfer Service. Mandiant. https:\/\/www.mandiant.com\/resources\/blog\/attacker-use-of-windows-background-intelligent-transfer-service."},{"key":"e_1_3_2_1_9_1","unstructured":"2023. Boot or Logon Autostart Execution: Registry Run Keys \/ Startup Folder Sub-technique T1547.001 - Enterprise | MITRE ATT&CK. https:\/\/attack.mitre.org\/techniques\/T1547\/001\/."},{"key":"e_1_3_2_1_10_1","unstructured":"2023. Create or Modify System Process: Windows Service Sub-technique TI543.OO3 - Enterprise j MITRE ATT&CK. https:\/\/attack.mitre.org\/techniques\/T1543\/003\/."},{"key":"e_1_3_2_1_11_1","unstructured":"2023. Hash and family of each sample in the Family Dataset. https:\/\/raw.githubusercontent.com\/eurecom-s3\/DecodingMLSecretsOfWindowsMalwareClassification\/main\/dataset\/malware."},{"key":"e_1_3_2_1_12_1","unstructured":"2023. Hexacorn j Blog Beyond Good Ol' Run Key - All Parts. https:\/\/www.hexacorn.com\/blog\/2017\/01\/28\/beyond-good-ol-run-key-all-parts\/."},{"key":"e_1_3_2_1_13_1","unstructured":"2023. Malware Development: Persistence - Part 4. Windows Services. Simple C++ Example. https:\/\/cocomelonc.github.io\/tutorial\/2022\/05\/09\/malware-pers-4.html."},{"key":"e_1_3_2_1_14_1","unstructured":"persistence-info.github.io 2023. Persistence-Info.Github.Io. persistence-info.github.io. https:\/\/persistence-info.github.io\/."},{"key":"e_1_3_2_1_15_1","unstructured":"PSBits 2023. Persistence with Windows Services. PSBits. https:\/\/gtworek.github.io\/PSBits\/services.html."},{"key":"e_1_3_2_1_16_1","unstructured":"2023. Startup Folder. https:\/\/persistence-info.github.io\/Data\/startupfolder.html."},{"key":"e_1_3_2_1_17_1","unstructured":"2024. Alpha Threat Blogs. http:\/\/www.blog.alphathreat.in\/."},{"key":"e_1_3_2_1_18_1","unstructured":"2024. Capa. https:\/\/mandiant.github.io\/capa\/."},{"key":"e_1_3_2_1_19_1","unstructured":"2024. CAPE: Malware Configuration And Payload Extraction. https:\/\/github.com\/kevoreilly\/CAPEv2."},{"key":"e_1_3_2_1_20_1","unstructured":"2024. HijackLibs. https:\/\/hijacklibs.net\/."},{"key":"e_1_3_2_1_21_1","unstructured":"2024. InQuest blog. https:\/\/inquest.net\/blog\/."},{"key":"e_1_3_2_1_22_1","unstructured":"2024. Malware Statistics & Trend Report. https:\/\/www.av-test.org\/en\/statistics\/malware\/."},{"key":"e_1_3_2_1_23_1","unstructured":"2024. Nasreddine Bencherchali blog. https:\/\/nasbench.medium.com\/."},{"key":"e_1_3_2_1_24_1","unstructured":"2024. Penetration testing lab blog. https:\/\/pentestlab.blog\/."},{"key":"e_1_3_2_1_25_1","unstructured":"2024. Wumb0in blog. https:\/\/wumb0.in\/."},{"key":"e_1_3_2_1_26_1","unstructured":"2025. Black Hat. https:\/\/www.blackhat.com\/."},{"key":"e_1_3_2_1_27_1","unstructured":"2025. BlackBerry ThreatVector Blog. https:\/\/blogs.blackberry.com\/en\/home."},{"key":"e_1_3_2_1_28_1","unstructured":"2025. CICADAS blog. https:\/\/cicada-8.medium.com\/."},{"key":"e_1_3_2_1_29_1","unstructured":"2025. Cocomelonc blog. https:\/\/cocomelonc.github.io\/."},{"key":"e_1_3_2_1_30_1","unstructured":"2025. Cyberark Threat Research Blog. https:\/\/www.cyberark.com\/resources\/threat-research-blog."},{"key":"e_1_3_2_1_31_1","unstructured":"2025. Cyble blog. https:\/\/cyble.com\/blog\/."},{"key":"e_1_3_2_1_32_1","unstructured":"2025. Google Cloud Blog. https:\/\/cloud.google.com\/blog."},{"key":"e_1_3_2_1_33_1","unstructured":"2025. HackTricks wiki. https:\/\/github.com\/HackTricks-wiki\/hacktricks\/."},{"key":"e_1_3_2_1_34_1","unstructured":"2025. hasherezade's 1001 nights. https:\/\/hshrzd.wordpress.com\/."},{"key":"e_1_3_2_1_35_1","unstructured":"2025. Helge Klein Blog. https:\/\/helgeklein.com\/blog-archive\/."},{"key":"e_1_3_2_1_36_1","unstructured":"2025. IBM X-Force. https:\/\/www.ibm.com\/think\/x-force."},{"key":"e_1_3_2_1_37_1","unstructured":"2025. MalwareBazaar. https:\/\/bazaar.abuse.ch\/."},{"key":"e_1_3_2_1_38_1","unstructured":"2025. Malwarebytes Labs. https:\/\/www.malwarebytes.com\/blog."},{"key":"e_1_3_2_1_39_1","unstructured":"2025. Matt Frisbie blog. https:\/\/substack.com\/umattfrisbie."},{"key":"e_1_3_2_1_40_1","unstructured":"2025. MDSec Insights. https:\/\/www.mdsec.co.uk\/knowledge-centre\/insights\/."},{"key":"e_1_3_2_1_41_1","unstructured":"2025. Me myself & IT. https:\/\/skanthak.hier-im-netz.de\/home.html."},{"key":"e_1_3_2_1_42_1","unstructured":"2025. Microsoft Learn. https:\/\/learn.microsoft.com."},{"key":"e_1_3_2_1_43_1","unstructured":"2025. MITRE ATT&CK. https:\/\/attack.mitre.org\/."},{"key":"e_1_3_2_1_44_1","unstructured":"2025. Oddvar Moe's blog. https:\/\/oddvar.moe\/."},{"key":"e_1_3_2_1_45_1","unstructured":"2025. PSBits. https:\/\/github.com\/gtworek\/PSBits."},{"key":"e_1_3_2_1_46_1","unstructured":"2025. The Red Canary Blog. https:\/\/redcanary.com\/blog\/."},{"key":"e_1_3_2_1_47_1","unstructured":"2025. Red Team Notes. https:\/\/www.ired.team\/offensive-security\/persistence."},{"key":"e_1_3_2_1_48_1","unstructured":"2025. Ristbs's blog. https:\/\/ristbs.github.io\/."},{"key":"e_1_3_2_1_49_1","unstructured":"2025. Securworks blog. https:\/\/www.secureworks.com\/blog."},{"key":"e_1_3_2_1_50_1","unstructured":"2025. Sigma. https:\/\/github.com\/SigmaHQ\/sigma."},{"key":"e_1_3_2_1_51_1","unstructured":"2025. Specterops blog. https:\/\/specterops.io\/blog\/."},{"key":"e_1_3_2_1_52_1","unstructured":"2025. Stmxcsr blog. https:\/\/stmxcsr.com\/."},{"key":"e_1_3_2_1_53_1","unstructured":"2025. ThreatDown Intelligence blog. https:\/\/www.threatdown.com\/blog\/."},{"key":"e_1_3_2_1_54_1","unstructured":"2025. Trustedsec Security Blog. https:\/\/trustedsec.com\/blog."},{"key":"e_1_3_2_1_55_1","unstructured":"2025. Unit 42 Threat Research. https:\/\/unit42.paloaltonetworks.com\/category\/threat-research\/."},{"key":"e_1_3_2_1_56_1","unstructured":"2025. VirusTotal. https:\/\/www.virustotal.com."},{"key":"e_1_3_2_1_57_1","unstructured":"2025. VirusTotal Blog. https:\/\/blog.virustotal.com\/."},{"key":"e_1_3_2_1_58_1","unstructured":"2025. Wietze Beukema blog. https:\/\/www.wietzebeukema.nl\/blog\/."},{"key":"e_1_3_2_1_59_1","unstructured":"2025. Windows OSHub. https:\/\/woshub.com\/."},{"key":"e_1_3_2_1_60_1","unstructured":"2025. Windows persistence. https:\/\/utwente-scs.github.io\/Sok-Windows-Malware-Persistence\/."},{"key":"e_1_3_2_1_61_1","unstructured":"2025. WithSecure Labs. https:\/\/labs.withsecure.com\/publications."},{"key":"e_1_3_2_1_62_1","unstructured":"2025. Zcaler blog. https:\/\/www.zscaler.com\/blogs?type=security-research."},{"key":"e_1_3_2_1_63_1","unstructured":"Kevin Almansa. 2017. DLL Proxying. InfoSec Blog. https:\/\/kevinalmansa.github.io\/application%20security\/DLL-Proxying\/."},{"key":"e_1_3_2_1_64_1","unstructured":"Ulrich Bayer Imam Habibi Davide Balzarotti Engin Kirda and Christopher Kruegel. 2009. A View on Current Malware Behaviors. In LEET."},{"key":"e_1_3_2_1_65_1","unstructured":"Wietze Beukema. 2023. Hijacking DLLs in Windows. https:\/\/www.wietzebeukema.nl\/blog\/hijacking-dlls-in-windows."},{"key":"e_1_3_2_1_66_1","volume-title":"Paulo L\u00edcio de Geus, and Andr\u00e9 Ricardo Abed Gr\u00e9gio","author":"Botacin Marcus Felipe","year":"2018","unstructured":"Marcus Felipe Botacin, Paulo L\u00edcio de Geus, and Andr\u00e9 Ricardo Abed Gr\u00e9gio. 2018. The other guys: automated analysis of marginalized malware. Journal of Computer Virology and Hacking Techniques 14 (2018)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616589"},{"key":"e_1_3_2_1_68_1","unstructured":"Deland-Han. 2025. Windows Registry for Advanced Users -Windows Server. https:\/\/learn.microsoft.com\/en-us\/troubleshoot\/windows-server\/performance\/windows-registry-advanced-users."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102550"},{"key":"e_1_3_2_1_70_1","volume-title":"Malware Persistence Mechanisms. Procedia Computer Science","author":"Gittins Zane","year":"2020","unstructured":"Zane Gittins and Michael Soltys. 2020. Malware Persistence Mechanisms. Procedia Computer Science (2020)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24475"},{"key":"e_1_3_2_1_72_1","unstructured":"last byte. 2024. PersistenceSniper. https:\/\/github.com\/last-byte\/PersistenceSniper."},{"key":"e_1_3_2_1_73_1","volume-title":"Kaibin Bao, Veit Hagenmeyer, and Wajih Ul Hassan.","author":"Liu Qi","year":"2024","unstructured":"Qi Liu, Muhammad Shoaib, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, and Wajih Ul Hassan. 2024. Accurate and scalable detection and investigation of cyber persistence threats. arXiv preprint arXiv:2407.1SS32 (2024)."},{"key":"e_1_3_2_1_74_1","volume-title":"Longitudinal Study of the Prevalence of Malware Evasive Techniques. arXiv preprint arXiv:2112.112S9","author":"Maffia Lorenzo","year":"2021","unstructured":"Lorenzo Maffia, Dario Nisi, Platon Kotzias, Giovanni Lagorio, Simone Aonzo, and Davide Balzarotti. 2021. Longitudinal Study of the Prevalence of Malware Evasive Techniques. arXiv preprint arXiv:2112.112S9 (2021)."},{"key":"e_1_3_2_1_75_1","volume-title":"Dwayne Van Eerd, and Emma Irvin","author":"Mahood Quenby","year":"2014","unstructured":"Quenby Mahood, Dwayne Van Eerd, and Emma Irvin. 2014. Searching for grey literature for systematic reviews: challenges and benefits. Research synthesis methods 5, 3 (2014), 221\u2013234."},{"key":"e_1_3_2_1_76_1","volume-title":"Classification of malware persistence mechanisms using low-artifact disk instrumentation. Ph. D. Dissertation","author":"Mankin Jennifer","unstructured":"Jennifer Mankin. 2013. Classification of malware persistence mechanisms using low-artifact disk instrumentation. Ph. D. Dissertation. Northeastern University."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24297"},{"key":"e_1_3_2_1_78_1","unstructured":"Mark Russinovich. 2024. Autoruns for Windows - Windows Sysinternals. https:\/\/docs.microsoft.com\/en-us\/sysinternals\/do wnloads\/autoruns."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.42"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37228-6_20"},{"key":"e_1_3_2_1_81_1","volume-title":"Proc. CYBERWARE","author":"Phillips Nicholas","year":"2022","unstructured":"Nicholas Phillips and A Ali Gombe. 2022. Sterilized Persistence Vectors (SPVs): Defense Through Deception on Windows Systems. Proc. CYBERWARE (2022)."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_4"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.23919\/ICAC50006.2021.9594197"},{"key":"e_1_3_2_1_84_1","volume-title":"Proceedings of the International Workshop on Ethics in Computer Security (EthiCS).","author":"Reidsma Dennis","unstructured":"Dennis Reidsma, Jeroen van der Ham, and Andrea Continella. 2023. Operationalizing Cybersecurity Research Ethics Review: From Principles and Guidelines to Practice. In Proceedings of the International Workshop on Ethics in Computer Security (EthiCS)."},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.14"},{"key":"e_1_3_2_1_86_1","volume-title":"AVClass: A Tool for Massive Malware Labeling. In International Symposium on Research in Attacks, Intrusions, and Defenses.","author":"Sebasti\u00e1n Marcos","year":"2016","unstructured":"Marcos Sebasti\u00e1n, Richard Rivera, Platon Kotzias, and Juan Caballero. 2016. AVClass: A Tool for Massive Malware Labeling. In International Symposium on Research in Attacks, Intrusions, and Defenses."},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427261"},{"key":"e_1_3_2_1_88_1","volume-title":"Proceedings of the International Conference on Security and Privacy in Communication Networks (SecureComm).","author":"Starink Jerre","year":"2023","unstructured":"Jerre Starink, Marieke Huisman, Andreas Peter, and Andrea Continella. 2023. Understanding and Measuring Inter-Process Code Injection in Windows Malware. In Proceedings of the International Conference on Security and Privacy in Communication Networks (SecureComm)."},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102855"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23019"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"crossref","unstructured":"Carsten Willems Thorsten Holz and Felix Freiling. 2007. Toward automated dynamic malware analysis using cwsandbox. (2007).","DOI":"10.1109\/MSP.2007.45"},{"key":"e_1_3_2_1_92_1","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Zhu Shuofei","year":"2020","unstructured":"Shuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin, Ziyi Zhang, Linhai Song, and Gang Wang. 2020. Measuring and modeling the label dynamics of online Anti-Malware engines. In Proceedings of the USENIX Security Symposium."}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3805971","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:38:38Z","timestamp":1780587518000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3805971"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":92,"alternative-id":["10.1145\/3779208.3805971","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3805971","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}