Accessibility Feature Binary Masquerading as Command Prompt
Detects the execution of known Windows accessibility binaries (e.g., sethc.exe, utilman.exe) where the internal metadata or original filename indicates that the process is actually cmd.exe. This is a common technique used by adversaries to gain unauthenticated command-line access with SYSTEM privileges via accessibility features, typically during the login screen process.
Microsoft Sentinel (KQL)

