Agent Skills: hunting-for-unusual-service-installations

Detect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.

UncategorizedID: plurigrid/asi/hunting-for-unusual-service-installations

Install this agent skill to your local

pnpm dlx add-skill https://github.com/plurigrid/asi/hunting-for-unusual-service-installations

Skill Files

Browse the full folder contents for hunting-for-unusual-service-installations.

Download Skill

Loading file tree…

Select a file to preview its contents.