Ransomware-Related Registry Changes

Detects multiple registry value set events where the registry value data contains keywords like 'ransom' or 'payment', or the registry key contains 'Run'. This behavior can indicate ransomware activity attempting to establish persistence or communicate its demands.