New TimeProviders Registered With Uncommon DLL Name (e88a6ddc-74f7-463b-9b26-f69fc0d2ce85)
Detects processes setting a new DLL in DllName in under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains.