906b392938
new: Suspicious Autorun Registry Modified via WMI update: Suspicious PowerShell Invocations - Specific - PowerShell Module update: Suspicious PowerShell Invocations - Specific update: Potential Persistence Attempt Via Run Keys Using Reg.EXE update: New RUN Key Pointing to Suspicious Folder update: Suspicious Powershell In Registry Run Keys update: Direct Autorun Keys Modification update: Suspicious Run Key from Download --------- Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com>