Post #4370467
2026-08-04 08:44 UTC
Jolie trouvaille du jour pour la chasse: suivre le lapin "Non-Sucking Service Manager" :)
via @malmoeb@infosec.exchange
"While analyzing Autoruns entries during a Compromise Assessment or an Incident Response case, would you take a second look at the nssm.exe binary running as a service? Hopefully. In a recent case, attackers used nssm.exe to start ngrok as a service to maintain a persistent backdoor. Here is a practical breakdown of how this mechanism works and how you can hunt for it in your environment."
👇
https://dfir.ch/posts/field_notes_nssm/
#infosec #dfir
Replies (0)
No replies.