LockAppHost tampers with Windows Update/Defender for mining
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
Microsoft Sentinel (KQL)

