Malicious Windows Service Creation via sc.exe Suspicious BinPath
Detects the creation or modification of Windows services using sc.exe where the binary path (binpath) points to suspicious or user-writable directories such as User profiles, AppData, Temp, or Public folders, which are often used by adversaries for persistence or privilege escalation.
SentinelOne

