Hunts for Windows persistence across autostart locations: Run keys, services, scheduled tasks, WMI event subscriptions, and startup folders, baselining them to surface anomalous or recently added entries. Activates for requests to hunt persistence, audit autostart extensibility points, or find malware autoruns on Windows.