XRed Backdoor Persistence via Synaptics.exe Run Key in ProgramData

Detects the creation or modification of Windows Registry run keys (Run or RunOnce) that attempt to point to executables within 'ProgramData\Synaptics' or named 'synaptics.exe'. This behavior is characteristic of adversaries attempting to establish persistence by masquerading as legitimate Synaptics driver software, while excluding legitimate installation directories.