RDP Service Enablement via Suspicious Parent Process

Detects the enablement of the Remote Desktop Protocol (RDP) by modifying registry keys or service configurations, specifically when triggered by identified remote access tools or common script interpreters (cmd, powershell, etc.) executing from non-standard user-writable paths such as Temp or AppData. This behavior is indicative of lateral movement preparation.