Persistence scanner
macOS equivalent
KnockKnock
Scans 22 Windows autostart families: registry Run keys, services and drivers, ServiceDll, scheduled tasks, Winlogon, AppInit, IFEO/SilentProcessExit, WMI subscriptions, startup folders, LSA packages, print monitors, credential providers, browser helper objects, COM hijacks and screensavers. Every image is Authenticode checked, with optional VirusTotal enrichment. It reads the command line too, not just the file: a signed Windows interpreter — rundll32, mshta, regsvr32, powershell — pointed at a remote location, a per-user path, an encoded script or a scriptlet is flagged even though the executable verifies perfectly, and scheduled tasks report their arguments so the DLL or script a task actually loads is visible.
ACTION → Inspect details, reveal the validated file location, or open Windows Startup apps.
LIMITS → A notable result is a signal to investigate, not proof of malware. The command-line check reads what is written. A payload assembled at runtime, or one that is neither remote, per-user nor encoded, is out of its reach.