Registry Run Key/Startup Folder Persistence to Suspicious Paths

Detects the creation or modification of Windows Registry Run/RunOnce keys or files within the Startup folder where the target command path is deemed suspicious (e.g., temp directories, ProgramData), utilizes known LOLBins, or contains common obfuscation flags (e.g., -enc, IEX, -w hidden) frequently associated with persistence mechanisms.