Suspicious Service DACL Modification Via Set-Service Cmdlet — Detection Rule

Detects suspicious DACL modifications via the "Set-Service" cmdlet using the "SecurityDescriptorSddl" flag (Only available with PowerShell 7) that can be used to hide services or make them unstopable

Read the full analysis on IntelFusions