BQTLock UAC Bypass via Fodhelper
Detects when fodhelper.exe, a legitimate Windows utility, is used to spawn processes other than cmd.exe or conhost.exe. This behavior is commonly associated with UAC bypass techniques where fodhelper.exe is abused to execute arbitrary commands with elevated privileges without a UAC prompt.
Microsoft Sentinel (KQL)

