Image File Execution Options (IFEO) Injection
Detects suspicious registry modifications for IFEO entries which can be used by attackers for persistence. This is based off of testing with Atomic Red Team tests - https://www.atomicredteam.io/atomic-red-team/atomics/T1546.012
Microsoft Sentinel (KQL)

