Detection rules › By eventService-Control-Manager event 70366 detection rules reference this event. View event page.Sigma (3)HackTool Service Registration or Execution severity high T1569.002 Remote Access Tool Services Have Been Installed - System severity medium T1543.003, T1569.002 Windows Defender Threat Detection Service Disabled severity medium T1562.001 Splunk (3)First Time Seen Running Windows Service T1569.002 Windows Cisco Secure Endpoint Related Service Stopped T1490 Windows Security And Backup Services Stop T1490