BYOVD sc.exe Kernel Driver Installation (T1068)

This rule detects the creation of a Windows service where the service type is set to 'kernel' via the sc.exe command-line utility. This behavior is indicative of an attempt to load a kernel driver or perform low-level system modifications, which is often used by rootkits or malicious drivers. The rule filters out known trusted publishers to reduce noise.