npm RAT Registry Run Key Persistence via csshost Value
Detects the creation or modification of a Registry Run key value named 'csshost'. This technique is commonly used by malware or persistent threats to achieve automatic execution upon system logon or boot by masquerading as or hijacking a host-related entry.
Microsoft Sentinel (KQL)

