Registry Run Key Persistence via Scripting Interpreters

Detects attempts to establish persistence by modifying registry run keys (Run or RunOnce) to execute scripting interpreters like PowerShell, cmd, or wscript. The rule looks for at least two such events within an hour on the same device and registry key, indicating potential malicious activity.