Backdoor Persistence via HKCU Registry Run Key

Detects the creation or modification of registry keys under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. These keys are commonly used by adversaries to achieve persistence by ensuring arbitrary programs or scripts execute automatically when the current user logs in.