Most Important Detection 2026: Registry Run Key and Startup Folder Persistence
Detects persistence modification via Registry Run/RunOnce keys or the addition of suspicious files to the Windows Startup folder. The rule specifically monitors for registry values pointing to common volatile directories, script extensions, or suspicious command-line interpreters. It also flags new executables or scripts being written directly into startup directory paths. This rule covers both direct registry manipulation and startup folder placement, often associated with malware or adversary persistence mechanisms.
CQL

