Sauron Loader domain/locale targeting check after keyroll side-load

Detects reconnaissance commands related to system domain, locale, and environment settings following the execution of rnpkeys.exe from C:\ProgramData\keyroll, a behavior associated with the Sauron Loader. The rule identifies suspicious system discovery commands (nltest, whoami, etc.) or environment checks performed shortly after the loader's execution, indicating potential target verification before C2 registration.