Suspicious termination of security product processes/services (AV killer)
This rule detects attempts to disable, terminate, or misconfigure security software, including antivirus, EDR, and endpoint protection solutions, by monitoring the execution of system administration binaries (such as taskkill, net, sc, wmic, powershell) with command-line arguments indicating service or process stopping, deletion, or configuration changes related to security-specific product names.
Microsoft Sentinel (KQL)

