title: test id: ff151c33-45fa-475d-af4f-c2f93571f4fe description: | condition and or status: experimental date: 2021/12/4 author: test logsource: product: windows service: security detection: selection1: EventID: 3 selection2: aaa: bbb selection3: ccc: ddd selection4: eee: fff timeflame: 2d condition: selection1 and selection2 and selection3 and selection4 falsepositives: - Unknown level: medium