Sauron Loader 'keyroll' Scheduled Task Persistence

Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.