LoFP LoFP / legitimate use of fodhelper.exe utility by legitimate user

Techniques

Sample rules

Bypass UAC via Fodhelper.exe

Description

Identifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.

Detection logic

condition: selection
selection:
  ParentImage|endswith: \fodhelper.exe