Suspicious Service Path Modification — Detection Rule

Detects service path modification via the "sc" binary to a suspicious command or path

Read the full analysis on IntelFusions