Lightlife RAT persistence via Run key 'WindowsUpdate' PowerShell entry

Detects the creation or modification of a Windows Registry 'Run' key that triggers a PowerShell script named 'Update.ps1' with hidden execution policies. The rule also captures direct execution of the same PowerShell script via process creation events.