Depending on the situation, there can be several ways to maintain access to a compromised system. If we are in a Pentest engagement, we should make sure that we **do not open up avenues where anyone can connect without any authentication**!
The best option here is to add a user to the system, if we realise that the customer is not detecting the noise we are making; `net user hacker password123 /add`
However, if we are in a red teaming situation, we might be able to do a bit more by running a persistence script using metasploit, or by having a schedules task to connect back to our machine.
## Metasploit
There are several tools available in metasploit to achieve persistence.
- `run persistence -h`
- `exploit/windows/local/persistence`
- `exploit/windows/local/registry_persistence`
## Scheduled Tasks
- `run scheduleme`
- `run schtaskabuse`