Malicious WpnUserHost/FontCacheExt service masquerading persistence
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
Microsoft Sentinel (KQL)

