indicatorregistry_key
HKLM\System\CurrentControlSet\Services\WindowsUpdateService
- First seen
- 2026-05-14
- Last seen
- 2026-05-14
- Sightings
- 1
Posts referencing this indicator
- Komari: The “Monitoring” Tool That Didn't Need Weaponising
Registry key for the deceptive Windows service created by NSSM to persist the Komari agent.