Startup Folder Item Creation

This KQL query identifies file creation events within common Windows startup directories and enriches them with Windows Shell Link (shortcut) creation activity. Startup folders are frequently abused by adversaries for persistence since files or shortcuts placed here automatically execute at user login. The query covers both system-wide and user-specific startup paths and can exclude known legitimate items via an exclusion list to reduce false positives.