Ransomware Series: Suspicious Registry Run Key / Startup Folder Persistence

Detects persistence attempts via Windows Registry run keys and Startup folders. The rule identifies suspicious modifications to run/runonce registry keys involving common user-writable paths (e.g., Temp, AppData) or the execution of PowerShell commands with common obfuscation flags (e.g., -enc). Additionally, it detects the creation of executable files (.lnk, .ps1, .vbs, .bat) within user Startup folders.