Forum Discussion
kevinh
22 days agoBronze III
Ransomware: Darkside - Question 9
In terms of determining the name of the service that is installed after the ransomware was executed, there doesn't seem to be any service installation activities observed from the endpoint. Wonde...
- 17 days ago
There is a different EventCode that indicates that "A service was installed in the system."
kevinh
22 days agoBronze III
When parsing for the service names during execution I am also struggling to find a meaningful link as well
Which includes parsing for the eventID itself