Suspicious Persistence via Registry Run Keys or Startup Folder
This rule detects potential persistence attempts by monitoring for the creation of suspicious registry values (common autostart locations) or new files in the Windows Startup directory. It flags registry value data or file names that match known suspicious patterns (e.g., PowerShell, cmd, temp/appdata paths, URLs) when executed by processes other than trusted installers.
Microsoft Sentinel (KQL)

