Suspicious Service Install/Config Pointing to Temp/AppData/ProgramData
Detects the creation or configuration of Windows services using sc.exe or PowerShell where the binary path points to suspicious, writable directories (Temp, AppData, or ProgramData). This behavior is often associated with persistence mechanisms where adversaries place malicious binaries in user-writable locations to execute with higher privileges.
SentinelOne

