Hunting For Unusual Service Installations

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.

thedixitjain 2d52902 4 files · 23.4 KB Updated 2 repo stars

File contents

thedixitjain/the-mega-skill-library/tree/main/library/security-and-compliance/hunting-for-unusual-service-installations commit 2d52902882

Frequently asked questions

npx skillmds add thedixitjain/hunting-for-unusual-service-installations