Malicious Windows service creation for SparroWocky persistence
Detects the creation of Windows services using sc.exe, powershell.exe, or cmd.exe that reference specific DLL files (winfsp-x64.dll or DukeQt.dll). This behavior is often associated with persistence mechanisms or DLL hijacking/side-loading techniques where a malicious service is configured to load a specific library.
Microsoft Sentinel (KQL)

