Active Setup StubPath Persistence in User-Writable Directories (T1547.014)

Detects modifications or creation of 'StubPath' registry values within the 'Active Setup\Installed Components' registry key, where the value points to suspicious, user-writable directories. This technique is commonly used to establish persistence by executing a malicious file upon user logon.