Suspicious Startup shell folder modification

Detects when adversaries attempt to modify the default Startup folder path to to circumvent runtime rules that hunt for file creations in the default Startup folder.

Back to all rules