Sauron Loader (rnpkeys.exe) spawning follow-on payload execution

Detects the Sauron Loader malware utilizing the process rnpkeys.exe as a parent to spawn common LOLBins (Living-off-the-Land Binaries) or execute payloads from temporary directories. This behavior is indicative of a secondary stage execution chain typical of the Sauron Loader.