CRPx0 fodhelper.exe UAC bypass via registry key hijack
Detects the UAC bypass technique using fodhelper.exe, where an adversary modifies the 'Software\Classes\ms-settings\shell\open\command' registry key to execute malicious code, followed by the execution of the fodhelper.exe binary, which inherently runs with elevated privileges.
YARA-L

