PowerShell registry Run key persistence for HEAVYGRAM implant
Detects instances where PowerShell is executed by a process masquerading as a common application (e.g., Telegram, WhatsApp, KeePass) to write a registry run key for persistence. This behavior is indicative of malicious installers or secondary stage delivery.
Splunk (SPL)

