UAC Bypass via fodhelper/computerdefaults Registry Shell Command Modification

Detects modifications to Windows Registry keys commonly associated with COM hijacking. Attackers modify these keys to redirect legitimate system calls to malicious executables, achieving persistence and potential privilege escalation. This rule monitors for registry value creation or modification in keys related to shell open commands for MS-settings, MSC files, or executables.