fodhelper.exe
Sources: 300M+ executions observed in the wild.
Summary
Features On Demand Helper. Manages Windows optional features (language packs, RSAT tools). Exploited as a well-known UAC bypass vector — it auto-elevates and reads a registry key that attackers can hijack.
fodhelper.exe is the 1578th most commonly executed Windows program in EchoTrail's dataset, observed 602 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by svchost.exe.
Get this in your tools
The same record for fodhelper.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/fodhelper.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 7e80da8d839dcf05e30317256460ed7a4ee25cab2750d768569aaab35e1e8c6461.9%
- b52fbb99308493a27aac725cf70721041cdee61caca19792b949cc0867a2796418.96%
- c546e05d705ffdd5e1e18d40e2e7397f186a7c47fa5fc21f234222d057227cf57.87%
- b1223b86d03c3583b84e46a9a6ad009d770fc4114640402ede19793167593a8f7.51%
- 4346962b31d93dd4e8b5164e6167bb030fc0ca7c77ec0bb6ab798a1e8cd9488e2.15%
- 8cb355417aa25ca3150f6df234c3341b91721e7be33cc044dad511a537695f8c0.54%
- a10c69e6268c4161d4d1fefb7629896f2026a1469ce4657dbcc684fd20a8053e0.36%
- eee3532d5338d41ce8e847612f96fe21321663da856c2de2a45cfdafbb27ba710.36%
- 25032d083bef92dab877d5eab9b28581962dbc9b43aa04820d8714728dc1064a0.18%
- 2b5089d56eb0ec9b2854102b5fe984f5be96756a170cc46774021e36b315edc30.18%
Process Ancestry
Top Grandparents
- services.exe97.89%
- powershell.exe2.11%
Top Parents
- svchost.exe99.5%
- cmd.exe0.5%
Top Children
- powershell.exe100%
Security Analysis
What does fodhelper.exe normally do?
Runs from C:\Windows\System32. Auto-elevates via its manifest (no UAC prompt). Normally launched via Settings app to manage optional Windows features. Infrequent execution.
When is fodhelper.exe suspicious?
Any execution outside of the Settings app context. Registry modifications to HKCU\Software\Classes\ms-settings\shell\open\command before fodhelper.exe runs. Spawning cmd.exe, powershell.exe, or any unexpected child process.
How do attackers abuse fodhelper.exe?
fodhelper.exe is one of the most reliable UAC bypass techniques. 1. UAC BYPASS: fodhelper.exe auto-elevates (runs as high-integrity without UAC prompt). Before execution, it checks HKCU\Software\Classes\ms-settings\shell\open\command for a default handler. An attacker sets this registry key to point to their payload (e.g., cmd.exe, powershell.exe, or malware). When fodhelper.exe runs, it launches the attacker's payload with elevated privileges. 2. ATTACK CHAIN: Typically reg.exe or PowerShell writes the registry key, then fodhelper.exe is launched. The payload inherits the elevated token. After execution, the registry key is cleaned up. Extremely common in commodity malware, RATs, and red team tools. Built into Metasploit, Cobalt Strike, and many post-exploitation frameworks.
Detection guidance
HIGH-CONFIDENCE DETECTIONS: - Registry modification of HKCU\Software\Classes\ms-settings\shell\open\command followed by fodhelper.exe execution - fodhelper.exe spawning cmd.exe, powershell.exe, or any unexpected child process - fodhelper.exe launched by anything other than explorer.exe or svchost.exe DATA SOURCES: Registry events (Sysmon 12/13/14), process creation (Sysmon 1)
False positive notes
Legitimate use is rare — most users access optional features through the Settings GUI. Direct fodhelper.exe execution is unusual even in normal operation.
Related Processes
Ask Rocky about fodhelper.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for fodhelper.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.