Unusual Service Instll

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.

undermybelt Updated

File contents

undermybelt/hermes-skills/tree/main/skills/red-teaming/anthropic-cybersecurity-skills/skills/unusual-service-instll commit 5bbe93947b

Frequently asked questions

npx skillmds@latest add undermybelt/unusual-service-instll