Suspicious Service Installation with Scripting Interpreters

This rule detects the installation of new Windows services (EventID 7045) where the service's executable path (ServiceFileName) contains common scripting interpreters like 'cmd', 'powershell', or 'wscript'. This pattern can indicate an adversary attempting to establish persistence or execute malicious code via a newly created service that leverages scripting capabilities.