Registry Run Key/Startup Folder Persistence to Suspicious Paths
This rule detects modifications to Windows Registry 'Run' or 'RunOnce' keys where the configured value points to a file located in common user-writable or temporary directories (AppData, Temp, ProgramData) with an executable extension (.exe, .dll, .scr, .bat, .vbs, .ps1, .cmd). This pattern is a common technique used by adversaries to establish persistence by ensuring malicious code executes automatically upon user login or system startup.
CQL

