Demystifying the “SVCHOST.EXE” Process and Its Command Line Options

Image for post
Image for post
Family Group Photo

The Service Control Manager (SERVICES.EXE)

Image for post
Image for post

The Service Host (SVCHOST.EXE)

Image for post
Image for post
Image for post
Image for post

The “K” Flag

Image for post
Image for post

The “S” Flag

Image for post
Image for post

The “P” Flag

Written by

#ThreatHunting #WindowsInternals #Malware #DFIR and occasionally #Python.

Get the Medium app