Good progress made on this so far. Four queries have been created to show evidence of Pysa being ran on the Windows system. Next, I have to make svchost.exe run in a temporary Windows directory so I can demonstrate a Query detecting it to the class and for the lesson. I also want to look into trying to get Windows Event Logs and try to get that working (no luck so far). Docs for what I have done can be found here.
Good progress made on this so far. Four queries have been created to show evidence of Pysa being ran on the Windows system. Next, I have to make svchost.exe run in a temporary Windows directory so I can demonstrate a Query detecting it to the class and for the lesson. I also want to look into trying to get Windows Event Logs and try to get that working (no luck so far). Docs for what I have done can be found here.