CRPx0 Fodhelper UAC Bypass via ms-settings Shell Command Registry Write

Detects unauthorized modification of the registry path 'HKCU\Software\Classes\ms-settings\Shell\Open\command'. This registry key is commonly hijacked by the 'fodhelper.exe' UAC bypass technique, where an attacker writes a malicious command to be executed with elevated privileges when the OS triggers the ms-settings protocol handler.