Registry Run Key Persistence via Suspicious Path or LOLBin
Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated file path points to suspicious directories (e.g., Temp, AppData, ProgramData, Users\Public) or utilizes living-off-the-land binaries (rundll32.exe, regsvr32.exe) residing outside of the protected System32 directory.
Splunk (SPL)

