ManageEngine Endpoint Central Suspicious Installation
Detects suspicious installations of ManageEngine Endpoint Central components (ManageEngineADSelfService.exe or me_servicelaunchpad.exe) when executed with silent installation parameters or initiated by scripting engines (wscript.exe, cscript.exe, powershell.exe), followed by the execution of 'reg.exe' or 'regsvcs.exe' within a two-hour window. This pattern can indicate an attempt to install or configure the software surreptitiously, potentially for persistence or privilege escalation.
Microsoft Sentinel (KQL)

