BigHugger
sk Skill · mukul975

hunting-for-unusual-service-installations

Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms via Sysmon/EDR telemetry. Use when hunting for new-service persistence after a suspected compromise, when Event ID 7045 fires for an unfamiliar service, or during incident response to enumerate service-based persistence…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
PythonWindows-servicesSysmonEvent-7045persistenceT1543.003service-installationthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python