Offline NTUSER.MAN Mandatory Profile Hive Forged via offreg.dll APIs by Non-Provisioning Process

Detects creation of a mandatory profile hive (NTUSER.MAN) matching the size produced by the RegLoadAppKeyW -> ORCreateKey/ORSetValue/ORSaveHive offreg.dll API sequence used to forge an offline registry hive for persistence, as observed with the TWINLOOT Python implant. TWINLOOT builds the offline hive via offreg.dll (RegLoadAppKeyW, ORCreateKey, ORSetValue, ORSaveHive) with Run key or COM hijack values baked in, then writes it to %USERPROFILE%\NTUSER.MAN so Windows loads it in preference to NTUSER.DAT at the next user logon, achieving persistence with no registry events, no admin privileges, and no visibility to standard tooling. Tightened to exclude the process image when it is a known legitimate profile-management or provisioning tool (USMT, SCCM, Intune Management Extension) that also uses offreg.dll to build NTUSER.MAN during normal mandatory/roaming profile deployment.