Dikshant Lather.
Our Story Write Sign In Get Started
Home Our Story Stories Blueprints Advisory Resume Contact
Home / Stories / Topic

System Services

Topic • 1 Story
Related: KQL Cloud Security Azure DevSecOps Entra ID Microsoft Sentinel AI Security Threat Hunting
Dikshant Lather Dikshant Lather · Sep 25, 2026

Uncovering Malicious Windows Service Installation via Event ID 7045 and Defender KQL

Catch lateral movement and persistence tools (PsExec, Cobalt Strike PsExec service) by monitoring new Windows Service installations with KQL.

Threat Hunting 2 min read
0 0
Uncovering Malicious Windows Service Installation via Event ID 7045 and Defender KQL
Dikshant Lather.

Cybersecurity Consultant specializing in CSPM, Microsoft Defender for Cloud, and AI Security architecture. Open for consulting advisory.

Directory

  • Home
  • Our Story & Bio
  • Resume & Certs
  • Advisory Services
  • Security Blueprints
  • Contact & Inquiries

Publications

  • All Stories
  • Become a Contributor
  • RSS 2.0 Feed
  • Atom 1.0 Feed
  • XML Sitemap

Dispatch

Briefings on CSPM playbooks, Azure hardening, and AI defense patterns.

© 2026 Dikshant Lather • All rights reserved.

Privacy Terms Cookies
ESC
Navigate ↑↓ • Select ↵
Dikshant Lather.