Registry Run Key Persistence via reg.exe or PowerShell
Detects modification or creation of Windows Registry Run keys by non-Microsoft signed instances of reg.exe, powershell.exe, or pwsh.exe. This activity is a common method for achieving persistence by ensuring malicious code executes automatically upon user login.
SentinelOne

