XHOPELESS Phase 0: AV/EDR Security Service Disabling

Detects attempts to stop or reconfigure critical Windows security services (such as WinDefend, WscSvc, Sense, and WdNisSvc) using the Service Control Manager (sc.exe) or by modifying service registry keys via reg.exe. This behavior is indicative of an adversary attempting to disable EDR/AV solutions to evade detection.