UAC bypass via fodhelper.exe registry hijack (Abyssos)
Detects the Abyssos UAC_BYPASS_FODHELPER technique: a ms-settings\Shell\Open\command registry value set immediately before fodhelper.exe launches an unsigned child payload, silently elevating to a high-integrity process without a UAC prompt.
Microsoft Sentinel (KQL)

