Persistence tactic [TA0003] used to maintain access to a compromised system across reboots involves making config changes that will re-execute a payload on a pre-defined trigger or event Registry Run Keys & Startup Folder [T1547.001] Logon Scripts [T1037.001] PowerShell Profile [T1546.013] Scheduled Tasks [T1053.005] Component Object Model Hijacking [T1546.015]