Allow Service Access Using Security Descriptor Tampering Via Sc.EXE — Detection Rule

Detects suspicious DACL modifications to allow access to a service from a suspicious trustee. This can be used to override access restrictions set by previous ACLs.

Read the full analysis on IntelFusions