Power Settings Modification for Persistence via powercfg.exe (T1653)
This rule detects the use of the 'powercfg.exe' utility by non-system accounts to modify power settings, such as disabling hibernation, modifying standby/sleep timeouts, or changing monitor/disk timeout configurations. Such actions can be indicative of attempts to maintain system availability, prevent the system from entering a low-power state that might terminate malicious processes, or ensure persistent execution of unauthorized activities.
Microsoft Sentinel (KQL)

