UAC Bypass via fodhelper.exe Spawning Shell or Script Engine

Detects instances where the Windows binary fodhelper.exe spawns various shell or utility processes. This behavior is a common indicator of a User Account Control (UAC) bypass attack, where the attacker leverages the auto-elevation property of fodhelper.exe to execute arbitrary commands with higher privileges.