def rule(event):
    if all(
        [
            event.deep_get("TargetObject", default="").endswith("\\Services\\WinDefend\\Start"),
            event.deep_get("Details", default="") == "DWORD (0x00000004)",
        ]
    ):
        return True
    return False
