Suspicious Registry Run Key Persistence via Scripting or LOLBins

Detects the creation or modification of Windows Registry Run keys that point to common LOLBins (Living Off the Land Binaries) like PowerShell, WScript, or MSHTA. This activity is often used for persistence, and the rule specifically excludes Microsoft-signed binaries to reduce false positives.