Suspicious Registry Run Key Modification

Detects suspicious modifications to Registry Run and RunOnce keys that include common scripting or command execution keywords (powershell, cmd, .bat). This activity is often associated with persistence mechanisms where adversaries attempt to execute malicious code upon user login.