HEAVYGRAM Autorun Registry Persistence via Known Payload Names

This rule detects the creation or modification of Windows Registry Run keys, which are a common technique used for achieving persistence. The rule specifically monitors for known suspicious or potentially malicious file names (e.g., RuntimeSSH.exe, MicDriver.exe, winappx.exe, MsCache.exe, smqdservice.exe) being added to Run locations, which triggers automatic execution upon user logon.