Suspicious RegSvcs.exe Execution and Child Processes

This rule detects potentially malicious usage of the Windows RegSvcs.exe binary, often used as a proxy for executing code. It monitors for two specific patterns: RegSvcs.exe being executed from user-writable directories (e.g., C:\Users\, C:\ProgramData\), or RegSvcs.exe spawning suspicious child processes (e.g., PowerShell, cmd, WScript, mshta), which is indicative of a living-off-the-land (LotL) attack technique to bypass application control or execute payloads.