sargx digital garden

Home

❯

Computer $h1t

❯

Blue Team

❯

Forensics

❯

Windows

Windows

Feb 17, 20261 min read

How to detect what command line spawned a process with no EDR-AV (Windows)

https://www.inversecos.com/2022/10/how-to-investigate-insider-threats.html

https://www.inversecos.com/2022/07/hunting-for-apt-abuse-of-exchange.html

https://www.inversecos.com/2022/05/how-to-perform-clipboard-forensics.html

https://www.inversecos.com/2022/04/defence-evasion-technique-timestomping.html

https://www.inversecos.com/2022/04/malicious-registry-timestamp.html


🌱 Back to Garden

1 item under this folder.

  • Feb 17, 2026

    How to detect what command line spawned a process with no EDR-AV (Windows)


    Created with Quartz v4.5.2 © 2026

    • GitHub
    • Discord Community