Persistence via Registry Run Key or Startup folder modification
Detects the creation or modification of Windows Registry Run key values or files dropped in the Startup folder, techniques commonly used by malware to establish persistence.
Microsoft Sentinel (KQL)

