Demo service that runs in svchost.exe
-
Updated
Jan 3, 2018 - C++
Demo service that runs in svchost.exe
A collection of powerful AQL (Ariel Query Language) queries for threat hunting, incident investigation, and security monitoring in IBM QRadar.
Case study + repeatable checks to detect and remove miner-like malware persisting as a random u###### service in Svchost DcomLaunch, with System32 artifacts.
Add a description, image, and links to the svchost topic page so that developers can more easily learn about it.
To associate your repository with the svchost topic, visit your repo's landing page and select "manage topics."