T1489: Everest Ransomware Mass AV/Backup/DB Service Disabling via sc.exe
Detects the use of the sc.exe utility to disable critical system, security, and database services, a technique commonly associated with Everest ransomware to prevent service restart during encryption activities.
Microsoft Sentinel (KQL)

