rnpkeys.exe Sauron Loader Spawns Secondary Payload Handlers from Temp

Detects instances where the rnpkeys process (likely used for GPG-related operations) spawns common Windows living-off-the-land binaries such as rundll32, regsvr32, msiexec, cmd, powershell, or wscript. It specifically monitors for patterns indicating potential script execution from temporary folders, the bypass of PowerShell execution policies, or the installation of products via msiexec, which may indicate malicious activity following initial compromise or delivery of a malicious payload.