Sauron Loader Repeated Chunked Network POSTs from rnpkeys.exe to C2

Detects anomalous, high-frequency outbound network connections to port 443 initiated by the binary 'rnpkeys.exe'. This behavior is characteristic of the Sauron Loader, which uses this masqueraded process to exfiltrate collected data, such as screenshots, via an encrypted C2 channel.