LockAppHost Spawns Suspended nslookup.exe/svchost.exe for Hidden Miner
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
Microsoft Sentinel (KQL)

