Deny Service Access Using Security Descriptor Tampering Via Sc.EXE — Detection Rule

Detects suspicious DACL modifications to deny access to a service that affects critical trustees. This can be used to hide services or make them unstoppable.

Read the full analysis on IntelFusions