Startup Registry Key Creation or Modification

This detection identifies attempts to establish persistence by modifying known Windows startup registry keys. These keys control which programs are automatically executed during system boot or user logon and are frequently abused by adversaries to maintain access across reboots. Analysts will need to tune the rule through testing and using the exclusion statements to remove noise of what is known good within their environments.