Sality-style AV process termination and security tool tampering
This rule monitors for suspicious activity targeting security software and host security configurations. It detects the termination of security-related processes using 'taskkill' or service management commands, the disabling of Windows Firewall via 'netsh', and the modification of critical Registry keys related to User Account Control (UAC), Registry editing access, and Task Manager functionality.
Microsoft Sentinel (KQL)

