T1037.001 Logon Script Persistence via Registry Modification

Detects suspicious modifications to Windows registry keys associated with logon script execution, such as 'UserInitMprLogonScript' or 'Userinit'. These locations are frequently abused by adversaries to achieve persistence by forcing the execution of malicious scripts or binaries upon user logon. The rule excludes modifications made by standard Microsoft Windows processes to reduce noise.