Has anyone found a good dictionary of Windows services and what each one actually does, impact if disabling, etc?
-
Show this thread
-
Replying to @mackwage
The problem is too many are generic to have a really good definitive list.
1 reply 0 retweets 3 likes -
Replying to @mikecherry @mackwage
I should clarify — too many use the same generic name, i.e., svchost
2 replies 0 retweets 3 likes -
Replying to @mikecherry @mackwage
I would point out that executables associated with stuff kicked off from svchost.exe is able to be gleaned from the system using a tool like sc.exe or services.msc. So it isn't really "using" that name, it is just not a stand-alone executable.
1 reply 0 retweets 2 likes -
The bigger challenge is that, especially where you rely upon vendor-supplied/managed PCs, there are a lot of services that aren't even part of Microsoft's ecosystem that may need to run.
1 reply 0 retweets 1 like -
Replying to @colemankane @mikecherry
Schuyler Retweeted Schuyler
@colemankane you beat me to it. :)https://twitter.com/mackwage/status/1345478185777942528 …Schuyler added,
2 replies 0 retweets 2 likes -
I just stumbled on this one. Seems pretty good. My focus is just Win stuff at the moment. http://batcmd.com/windows/10/services/ …
1 reply 0 retweets 4 likes -
Replying to @mackwage @mikecherry
This is a really nice list - you could probably even use something like this to build a reference table to compare against to identify hijacked services.
1 reply 0 retweets 1 like
I agree! Though for efficiency sake, I am focusing solely on the services which use SMS MFA because that's obviously an entry point
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.