File Dropped into Windows Startup Folder for Persistence
Detects the creation of files within the Windows Startup directory. Adversaries use this folder to achieve persistence by ensuring that malicious files or shortcuts are executed automatically when a user logs in.
SentinelOne

