Windows Persistence via Registry Run Key Referencing Suspicious Temp Path
Detects creation of an HKCU Run key value whose data references a temp or AppData temp path, consistent with the Windows persistence step of the botking implant after the build-time payload drop.
Sigma

