UAC Bypass Attempts Post-RDP

This rule detects attempts to bypass User Account Control (UAC) using specific Windows executables (eventviewer.exe, fodhelper.exe, computerdefaults.exe, slui.exe) initiated by cmd.exe or powershell.exe. The rule specifically looks for these executables being run from non-standard system directories, indicating a potential UAC bypass technique often observed after an initial compromise, such as via RDP.