Service Registry Key Deleted Via Reg.EXE — Detection Rule

Detects execution of "reg.exe" commands with the "delete" flag on services registry key. Often used by attacker to remove AV software services

Read the full analysis on IntelFusions