Suspicious Svchost Process Access — Detection Rule

Detects suspicious access to the "svchost" process such as that used by Invoke-Phantom to kill the thread of the Windows event logging service.

Read the full analysis on IntelFusions