Registry Run/RunOnce Key Persistence Write (T1547.001)
Detects the creation or modification of Windows Registry Run or RunOnce keys, which are commonly used for persistence to execute malicious code automatically upon user logon. The rule excludes common, legitimate software installers and trusted publishers located in Program Files to minimize false positives.
SentinelOne

