Windows Service Creation with Suspicious svchost Path
This rule detects the creation of a new Windows service (EventID 7045) where the service executable path contains both 'System32' and 'svchost', and the service description is either empty or contains 'Network'. This combination of characteristics can indicate the installation of a malicious service, potentially a backdoor or trojan, attempting to masquerade as a legitimate system service.
Microsoft Sentinel (KQL)

