Security Product Process Termination via taskkill or sc stop - T1562.001
Detects attempts to terminate security-related processes or stop security-related services using common administrative tools like taskkill.exe, sc.exe, net.exe, or net1.exe. This activity is often indicative of an adversary attempting to disable security monitoring and protection software to facilitate further malicious actions.
Microsoft Sentinel (KQL)

