I would like to demonstrate how easy it is to find a modern malware based solely on its persistence mechanism even if the AV ignores it. During my presentation I will show some live demo about active and infamous malwares focusing on their persistence. I would also like to show and publish a tool I have developed to query the different persistence mechanisms from a corporate environment which makes it easy to filter out the odd one out.