Forum Discussion
kevinh
19 hours agoBronze III
Ransomware: Darkside - Question 9
In terms of determining the name of the service that is installed after the ransomware was executed, there doesn't seem to be any service installation activities observed from the endpoint. Wondering if I should be focusing on a different code, slightly irrelevant towards service creation activities.
when searching for file creation for possible service names "api-ms-win-service-management-l1-1-0.dll" is also showcased to not work.
Wondering about what different area should I be looking into instead
1 Reply
- kevinhBronze III
When parsing for the service names during execution I am also struggling to find a meaningful link as well
Which includes parsing for the eventID itself