RunMRU Registry Key Deletion - Registry (3a9b8c1e-5b2e-4f7a-9d1c-2a7f3b6e1c55)
Detects attempts to delete the RunMRU registry key, which stores the history of commands executed via the run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.