Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
This rule detects a suspicious sequence of activities that potentially indicates an attempt to exploit Common Log File System (CLFS) vulnerabilities or manipulate cloud filter drivers for privilege escalation. The rule monitors for a correlation between Registry modifications involving Cloud Filter settings (HKLM\SYSTEM\CurrentControlSet\Services\CldFlt) and the creation or modification of specific CLFS-related files (.blf, .blf2, .regtrans-ms) occurring within a 10-minute window, with an optional check for symbolic link manipulation (NtCreateSymbolicLinkObject).
Microsoft Sentinel (KQL)

