WDigest UseLogonCredential Registry Downgrade via reg.exe or PowerShell

Detects modifications to the WDigest UseLogonCredential registry value, which is a known technique to force Windows to store plaintext credentials in memory. This is often performed by adversaries using tools like Mimikatz to facilitate credential dumping from the LSASS process.