Skip to main content

hunting-for-unusual-service-installations

Detects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms via Sysmon/EDR telemetry. Use when hunting for new-service persistence after a suspected compromise, when Event ID 7045 fires for an unfamiliar service, or during incident response to enumerate service-based persistence on Windows hosts.

インストールへ移動

ソース情報

リポジトリ
mukul975/Anthropic-Cybersecurity-Skills
ソースの最終更新活動
2026年8月2日 16:32
検出された SKILL.md の言語
英語
スター
27,732
フォーク
3,366

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。