Persistence via HKCU Run key modification
Detects additions or modifications to the Registry 'Run' keys in HKEY_CURRENT_USER, which are a common technique used by malware and adversaries to achieve persistence by automatically executing programs upon user logon.
Microsoft Sentinel (KQL)

