Suspicious Service Install/Config Pointing to Temp/AppData/ProgramData

Detects the creation or configuration of Windows services using sc.exe or PowerShell where the binary path points to suspicious, writable directories (Temp, AppData, or ProgramData). This behavior is often associated with persistence mechanisms where adversaries place malicious binaries in user-writable locations to execute with higher privileges.