Unusual file written in Startup folder

Identifies suspicious files written to the startup folder that would allow adversaries to maintain persistence on the endpoint.

Back to all rules