Persistence is the attacker’s best friend and the defender’s nightmare. This session will draw on real-world incident response to show how intruders persist across endpoints, AD, and cloud. Attendees will learn to hunt artifacts, trace actions, and apply checklists to expose what attackers hope to hide, with fresh research on Automatic Destinations and the USN Journal.