IH-PERSIST-001highPersistence

Persistence mechanism

Scheduled tasks, login hooks, and shell startup files keep code running after the skill is closed.

What does IH-PERSIST-001 flag?

Flags concrete ways to keep code running after the skill is closed: cron, launchd, systemd, shell startup files, Windows Run keys, scheduled tasks, git hooks and the Startup folder.

  • crontab with -e, -l or -r, or with a .cron file.
  • LaunchAgents or LaunchDaemons paths.
  • systemctl enable or start, and WantedBy= or ExecStart= unit lines.
  • Appending or writing to .bashrc, .zshrc, .profile or .bash_profile.
  • Windows CurrentVersion\Run keys, schtasks /create, git hook paths (pre-commit, post-commit, pre-push) and the Startup folder.

Why it matters

Persistence turns a one-time mistake into a lasting compromise. Unit 42 described auto-updater skills that registered cron jobs so the attacker's channel survived after the skill was removed.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Scheduler
Flagged
crontab -e
Ordinary file write
Not flagged
Write the notes to notes/today.md

Can IH-PERSIST-001 fire on a safe skill?

  • Operations skills that legitimately manage services.
  • Docs that explain how to list cron jobs with crontab -l.

How do I fix an IH-PERSIST-001 finding?

  • Remove the persistence step.
  • A skill should not install itself into login or scheduler configuration.

How do I tune or allow IH-PERSIST-001?

For an operations skill that manages services on purpose, review it by hand and lower the severity for that project with ruleOverrides.

{
  "ruleOverrides": {
    "IH-PERSIST-001": {
      "severity": "low"
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-PERSIST-001.

What can IH-PERSIST-001 miss?

  • Persistence through agent memory or configuration. IH-INJ-003 and IH-INT-004 cover parts of that.
  • Mechanisms that are not on the list, such as at jobs, login items added by script, or browser extensions.
  • Commands assembled at run time.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules