Registry Credential Hunting via reg.exe Query or PowerShell Get-ItemProperty (T1012/T1552.002)

This rule detects unauthorized or suspicious queries against Windows Registry paths known to contain sensitive information, including security hives (SAM, SECURITY), application-specific secrets (PuTTY, OpenSSH, RealVNC), and system autologon credentials. It monitors both command-line executions of 'reg.exe' and PowerShell commands targeting these registry keys.