Windows Various Notes

"C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe" SignatureUpdate -ScheduleJob -RestrictPrivileges

"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /c

C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.24081.51.0_x64__cw5n1h2txyewy\CrossDeviceService.exe

C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe | Microsoft Network Realtime Inspection Service

Get-Item Registry::HKEY_CLASSES_ROOT\ms-* | Out-String | select-string -Pattern "URL" -SimpleMatch

https://pentestlaboratories.com/2020/05/26/appdomainmanager-injection-and-detection/

Last updated

Was this helpful?