Ransomware-Related Registry Changes
Detects multiple registry value set events where the registry value data contains keywords like 'ransom' or 'payment', or the registry key contains 'Run'. This behavior can indicate ransomware activity attempting to establish persistence or communicate its demands.
Microsoft Sentinel (KQL)

