HEAVYGRAM PowerShell Defender Exclusion and Registry Persistence

This rule detects potentially malicious activity where specific non-standard processes (e.g., RuntimeSSH.exe, MicDriver.exe, MsCache.exe) either execute PowerShell commands related to security feature tampering (disabling Windows Defender exclusions) or create persistent Registry run keys associated with these process names. This pattern is indicative of malware attempting to establish persistence or evade security controls.