XWorm RAT Persistence via Run Key and USB Autorun.inf Creation
This rule detects two common persistence techniques: the modification of Windows Registry Run keys with paths referencing temporary or application data directories, and the creation of autorun.inf files on removable or non-system drives to facilitate potential code execution upon media insertion.
Microsoft Sentinel (KQL)

