Sauron Loader DLL Side-Loading via rnpkeys.exe in ProgramData\keyroll

Detects the execution of the process 'rnpkeys.exe' initiated by 'msiexec.exe' from the '\ProgramData\keyroll\' directory. This activity may indicate malicious use of the Windows Installer to proxy the execution of unauthorized or potentially malicious key management software.