UAC Bypass via fodhelper.exe Registry Manipulation (T1548.002)

Detects modifications to the 'Software\Classes\ms-settings\shell\open\command' registry key, a technique commonly used to bypass User Account Control (UAC). By setting the default handler for the ms-settings protocol to a malicious command, an attacker can achieve elevated execution when the protocol is triggered by a legitimate Windows component.