Operation DragonReturn: MixedSvc DcRAT Injection into svchost.exe via Mixed Reality.exe

This rule detects suspicious activity associated with the 'MixedSvc' service and potential DLL side-loading. It identifies the creation of a Windows service named 'MixedSvc' using sc.exe, the execution of 'Mixed Reality.exe' from a Windows Media Player directory, the side-loading of 'nvdaHelperRemote.dll' within the Windows Media Player directory, and the execution of svchost.exe with 'Mixed Reality.exe' as its parent/causality actor, which is indicative of malicious injection and persistence mechanisms.