CRPx0 UAC Bypass via fodhelper.exe ms-settings Registry Hijack
Detects modifications to the 'HKCU\Software\Classes\ms-settings\shell\open\command' registry key, a technique used to hijack the fodhelper.exe binary to achieve silent UAC elevation. This allows attackers to execute commands with administrative privileges without triggering a UAC prompt.
YARA-L

