Malicious WpnUserHost service creation for persistence
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
Microsoft Sentinel (KQL)

