Persistence techniques survive reboots — scheduled tasks, registry run keys, Windows services, DLL hijacking, cron jobs, SSH authorized_keys, WMI subscriptions, startup folder items.
Autoruns (Sysinternals) shows all persistence points in Windows. Monitor: registry run keys (HKLM/HKCU Run), scheduled tasks, new services, startup directories. EDR alerts on new/modified persistence mechanisms.