Persistence via Registry Run Key or Startup folder modification

Detects the creation or modification of Windows Registry Run key values or files dropped in the Startup folder, techniques commonly used by malware to establish persistence.