Windows Persistence via Registry Run Key Referencing Suspicious Temp Path

Detects creation of an HKCU Run key value whose data references a temp or AppData temp path, consistent with the Windows persistence step of the botking implant after the build-time payload drop.