SparroWocky ProcAuditManager malicious service persistence
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
Microsoft Sentinel (KQL)

