Registry Run Key or Startup Folder Persistence via Temp/AppData

Detects persistence attempts by monitoring modifications to Windows registry run keys (Run, RunOnce, Winlogon Shell/Userinit) or file creation within the Startup folder. It alerts when these locations are updated to reference suspicious file paths (Temp/AppData) or execute scripts (vbs, ps1, js, wsf, bat, hta).