BeepRAT Defense Evasion - Security Tool Tampering from AppData/TCC

This rule detects attempts to disable or interfere with endpoint security products, including Windows Defender and various third-party antivirus agents. It identifies suspicious process executions involving command-line tools like sc.exe, net.exe, or taskkill.exe targeting security services, or the direct modification of Windows registry keys associated with security policy disabling. The detection is further scoped to processes originating from or associated with common suspicious paths (e.g., AppData) or known malicious naming patterns.