REVSTEALER Modules Registry Run Key Persistence
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
Microsoft Sentinel (KQL)

