I scripted collection of running services and Windows Run-registry entries, then passed the output to an agent for review. The workflow brings candidate persistence signals together for examination alongside the wider incident evidence.
Viewed
UK Water Utility
Collect evidence of possible persistence
Extend Defender Live Response with PowerShell and KQL
Return to the full story ←