Grouped by Detection Method
MITRE ATT&CK Framework: New Service (T1050), Service Execution (T1035)
- Service creation can be used by an adversary to achieve persistence.
- Anomalous Services
- Newly observed Service File Name, Service Account
- Windows Security Event ID 4697