DragonReturn DcRAT MixedSvc Registry Service Persistence (T1543.003)
Detects the creation or modification of Windows services related to 'MixedSvc' or 'MixedRealitySvc' registry keys performed by non-standard processes. The rule specifically flags registry keys that point to suspicious directories such as AppData, Temp, ProgramData, or Windows Media Player, which is indicative of persistence mechanisms used by malware like DcRAT.
SentinelOne

