Remcos RAT Persistence via Registry Run Key or Remcos Key Creation

Detects potential persistence or configuration activity associated with the Remcos Remote Access Trojan (RAT). The rule monitors for the creation or modification of registry keys explicitly named 'Remcos', as well as the addition of executables from suspicious paths (e.g., AppData, Temp) to the Windows 'Run' registry keys, a common technique for achieving persistence.