XHOPELESS IFEO Debugger Hijack of Admin/Diagnostic Tools

Detects the creation or modification of Registry values under 'Image File Execution Options' (IFEO) that register a debugger for common administrative or diagnostic tools (e.g., Task Manager, Registry Editor, PowerShell). This technique can be used by malicious actors like XHOPELESS to intercept, block, or hijack the execution of legitimate tools, often to maintain persistence or impair security analysis.