Detects when an adversary uses the reg.exe utility to add or modify new keys or subkeys
Read the full analysis on IntelFusions