Loader enumerates Huorong processes and downgrades their token privileges
This rule detects potential tampering with the Huorong security product by monitoring for specific process names (HipsTray.exe, HipsMain.exe, HipsDaemon.exe, wsctrlsvc.exe, TrafficProt.exe) interacting with suspicious API calls or command lines indicative of token privilege manipulation, service blinding, or security product disabling/downgrade.
Microsoft Sentinel (KQL)

