Malicious MSI Installer Staging keyroll Directory (rnpkeys.exe/rnp.dll/tdwp.dll)

Detects the execution or presence of a malicious MSI installer file used by the Sauron Loader. This rule identifies files that exhibit the MSI OLE compound file structure in conjunction with specific file paths (C:\ProgramData\keyroll) and the presence of identified malicious components (rnpkeys.exe, rnp.dll, and tdwp.dll), or matches known SHA256 file hashes associated with this loader.