This repository contains three parts.
wmi_etw.pyis the Cape plugin to detect WMI interactions with Cape Sandbox.capa-rulescontains our Capa rules that can be used to detect persistence within Cape reports.persistence_hunter.pyis the tools to that can be used to detect unknown persistence techniques.data_analysiscontains the data and analysis scripts.docscontains the github pages website.
For the overview of persistence techniques visit [https://utwente-scs.github.io/Sok-Windows-Malware-Persistence/].