NSIS-dropped fake companion app persists via Run key (NW.js)
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
Microsoft Sentinel (KQL)

