MSI Drops Sauron Loader Staging Files into C:\ProgramData\keyroll
Detects the execution of msiexec.exe performing the installation or staging of specific binary files (rnpkeys.exe, rnp.dll, and tdwp.dll) into the C:\ProgramData\keyroll\ directory, which is a known behavior associated with the Sauron Loader malware.
Sigma

