SnakeBiteAgent keylogger persistence and credential store access

This rule monitors for three distinct suspicious behaviors on Windows endpoints: the addition of executable files from temporary or user-writable directories to Windows registry run keys for persistence, the creation of repeated hidden log or data files in AppData directories, and unsigned processes accessing browser-related credential storage files.