Windows File Association Modification via Ftype — Detection Rule

This analytic detects the use of the `ftype` command to modify Windows file associations. Attackers can abuse this functionality to change how specific file types are handled, potentially redirecting legitimate file execution to malicious payloads. If confirmed malicious, this behavior may enable persistence, execution of unauthorized code, or evasion of security controls.

Read the full analysis on IntelFusions