Forum Discussion
kevinh
20 hours agoBronze III
Ransomware: Darkside - Question 9
In terms of determining the name of the service that is installed after the ransomware was executed, there doesn't seem to be any service installation activities observed from the endpoint. Wonde...
kevinh
19 hours agoBronze III
When parsing for the service names during execution I am also struggling to find a meaningful link as well
Which includes parsing for the eventID itself