Rapuncel-style Windows Service Persistence for Stealer Kill-Loop

Detects the creation of a new Windows service using the service control manager command-line utility (sc.exe). This command is commonly used by attackers to achieve persistence by creating services that execute malicious binaries at startup, or to run processes with SYSTEM privileges.