Suspicious Windows Service Creation for Persistence (T1543.003)

This rule detects the creation of new Windows services (Event IDs 7045 and 4697) where the service binary path points to potentially suspicious locations such as user profiles, temp directories, program data, or common command interpreters. This pattern is frequently used by adversaries for persistence mechanisms or to deploy malicious drivers/tools.