GIFTEDCROOK - Malicious LNK Persistence Created in Windows Startup Folder via WinRAR ADS

This rule detects the creation of shortcut (.lnk) files within the Windows Startup folder initiated by potentially suspicious processes such as WinRAR, unrar, or PowerShell. This behavior is indicative of an attempt to achieve persistence by ensuring the execution of a malicious file upon user login.