BeepRAT Registry Query for System Recon via HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion

Detects registry enumeration activities targeting HKLM software keys related to Windows versioning and system configuration. This pattern is characteristic of BeepRAT post-compromise reconnaissance, where an adversary attempts to gather system information to profile the environment.