RegSvcs abuse and suspicious child processes
Detects instances of the Windows utility RegSvcs.exe being executed from suspicious, user-writable directories (such as Temp or Public folders) or instances where RegSvcs.exe is used to spawn common command-line or scripting tools, which is a common indicator of living-off-the-land binary (LOLBin) abuse.
Microsoft Sentinel (KQL)

