Ransomware Series: PsExec & Remote Service Creation for Mass Deployment
Detects the use of PsExec or SC.exe to create services on multiple remote endpoints within a short time window. This pattern is characteristic of adversary-driven mass deployment of ransomware or other malicious payloads where remote execution via Windows service control is used to move laterally across a network.
Microsoft Sentinel (KQL)

