Driver Service Installed from .sys Staged in Temp Directory

Detects the creation of a Windows service that points to a .sys file located in common temporary directories (Temp, Windows\Temp). This behavior is characteristic of adversaries attempting to load malicious kernel drivers, often for persistence or privilege escalation, such as in Bring Your Own Vulnerable Driver (BYOVD) attacks.