HEAVYGRAM PowerShell EncodedCommand Sets HKCU Run Key Persistence
Detects the use of PowerShell with the EncodedCommand parameter to modify or create entries in the HKEY_CURRENT_USER Run registry keys, a technique used by the HEAVYGRAM malware for persistence.
Sigma

