Potential threat actor tampering with Sysmon manifest and eventually disabling it
Read the full analysis on IntelFusions