Registry Run Key Persistence via Suspicious Path or LOLBin

Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated file path points to suspicious directories (e.g., Temp, AppData, ProgramData, Users\Public) or utilizes living-off-the-land binaries (rundll32.exe, regsvr32.exe) residing outside of the protected System32 directory.