Most Important Detection 2026: Registry Run Key and Startup Folder Persistence

This rule detects persistence mechanisms by monitoring additions to Windows Registry Run keys or files created in the user's Startup directory. It specifically flags entries that target suspicious locations (e.g., Temp, AppData, Public) or attempt to execute encoded commands using PowerShell or CMD.