Services
Overview
Legitimate Uses
Abuse by Threat Actors
Examples of Suspicious Entries
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RandomServiceName] "DisplayName"="Suspicious Service" "ImagePath"="C:\\Users\\Public\\malware.exe" "Start"=dword:00000002"ImagePath"="C:\\Windows\\system32\\legitservice.exe -k C:\\Windows\\Temp\\malware.exe""ServiceDLL"="C:\Users\Public\malicious.dll"
Detection and Analysis
Last updated