HEAVYGRAM Persistence via Autorun Registry Run Key Payloads

This rule detects potential persistence and execution activity associated with the HEAVYGRAM implant. It monitors for registry value modifications in the Windows Run keys by known malicious file names, as well as process execution events where those same files are executed with command-line arguments typically used for registry manipulation.