XHOPELESS Winlogon Shell/Userinit Registry Hijack

Detects modifications to the Winlogon Shell or Userinit registry keys. These keys are commonly used by adversaries for persistence to execute malicious binaries or scripts upon user logon.