Radmin registry hive copied to WOW6432Node via reg copy

Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.