Potential Persistence Attempt Via Run Keys Using Reg.EXE — Detection Rule

Detects suspicious command line reg.exe tool adding key to RUN key in Registry

Read the full analysis on IntelFusions