Koos's Tech Blog
  • Home
  • Recent Posts
  • About
  • Posts
  • Notes
  • Dark Theme
    Light Theme Dark Theme System Theme
  • Tags
  • Advanced Hunting
  • ASR
  • BG
  • Break the Glass
  • Configuration
  • Create Your Own Tools
  • Defender for Endpoint
  • Defender Vulnerability Management
  • Endpoint
  • Exposure Management
  • Governance
  • Identity Security
  • Investigation
  • KQL
  • Microsoft Defender for Endpoint
  • PowerShell
  • Registry
  • Service Hardening
  • SOC
  • Triage
  • TVM
  • VPN
Hero Image
Finding Weak Service Executable Paths with Defender TVM and PowerShell

Microsoft Defender can flag services that run outside common protected locations. This post shows how to use KQL to identify the affected service paths and PowerShell to validate whether the base folders are writable by broad user groups.

  • Defender for Endpoint
  • Defender Vulnerability Management
  • Exposure Management
  • KQL
  • PowerShell
  • Service Hardening
Friday, May 8, 2026 | 12 minutes Read
Navigation
  • Recent Posts
  • About
Contact me:
  • koos@koosjanse.com
  • Koosjuh

Stay up to date with email notification


By entering your email address, you agree to receive the newsletter of this website.

Toha Theme Logo Toha
© 2026 Copyright.
Powered by Hugo Logo