Windows_Hacktool_WinPEAS_ng_4a9b9603
Description
WinPEAS detection based on the dotNet binary, Services info module
Query · yara
strings:
$win_0 = "Services Information" ascii wide
$win_1 = "Interesting Services -non Microsoft-" ascii wide
$win_2 = "FilteredPath" ascii wide
$win_3 = "YOU CAN MODIFY THIS SERVICE:" ascii wide
$win_4 = "Modifiable Services" ascii wide
$win_5 = "AccessSystemSecurity" ascii wide
$win_6 = "Looks like you cannot change the" ascii wide
$win_7 = "Checking write permissions in" ascii wide
condition:
4 of them