Windows Agent Persistence Issues #3349
CyberSecNB
started this conversation in
General
Replies: 1 comment
-
|
The typical deployment options you'll see in Caldera are not meant to persist across target host reboots. If you're interested in persistence across reboots, there are a few options on Windows:
In terms of what's recommended, it depends on what you want to test or detect. Each of these methods will generate different telemetry, so if you're basing this activity on a specific adversary or trying to test a specific analytic, you'll have to choose accordingly. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I've begun to look at ways to keep agents alive for prolonged periods of time in my lab. Using the Sandcat agent and PowerShell deployment on Windows endpoints works fine, but after a client reboot the agents show as dead. If I re-run the installer a new Agent is created in the caldera console and the old one shows as dead/untrusted.
Is there a recommended deployment model to maintain agent persistence?
Beta Was this translation helpful? Give feedback.
All reactions