Rapuncel Persistence via Windows Service Auto-Start with AV/EDR Kill Loop

This rule detects the installation of a new Windows service (Event ID 7045 or 4697) with an 'auto start' configuration that is immediately followed by the termination of multiple processes (either 'services.exe' or the service's own image file) within a 60-minute window on the same host. This pattern can indicate an unstable or malicious service deployment that causes system instability or performs rapid cleanup.