AppCertDLLs Registry Key Persistence (T1546.009)

Detects the creation or modification of registry values within the AppCertDlls registry key. Adversaries use this technique to achieve persistence by forcing malicious DLLs to be loaded into every process that calls common Windows API functions such as CreateProcess.