Hunting For Unusual Service Installations

Use when detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms. Use when detecting suspicious windows service installations (mitre att&ck t1543.003) by parsing.

oyi77 9311a19 4.3 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/hunting-for-unusual-service-installations commit 9311a19c63

Frequently asked questions

npx skillmds add oyi77/hunting-for-unusual-service-installations