PlugPlay Service Binary Path Hijack via sc.exe (AdaptixC2 Lateral Movement)
Detects modifications to the 'PlugPlay' Windows service using 'sc.exe', specifically involving changes to the binary path (binpath) and subsequent service status changes (start/stop) within a short timeframe (30 minutes). This behavior is often associated with the persistence or hijacking of services to execute malicious files, specifically targeting Microsoft Office or Copilot-related process names.
Microsoft Sentinel (KQL)

