UAC Bypass via Fodhelper Registry Key Manipulation

Detects modifications to the Windows Registry subkeys associated with the 'ms-settings' URI scheme, which are targeted by the 'fodhelper.exe' UAC bypass technique. The rule correlates registry operations in HKCU with the execution of fodhelper.exe to identify attempts to elevate privileges without triggering a UAC prompt.