Quick Share Use-After-Free Crash Indicator - WER vtable Hijack Attempt
This rule detects Windows application crash events (Event IDs 1000 and 1001) specifically for 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. The detection triggers when the crash description contains indicators of memory-related instability, such as access violations, heap corruption, or invalid virtual calls, which may suggest exploitation attempts or service instability.
Microsoft Sentinel (KQL)

