ShieldBreak Exploit SYSTEM Privilege Escalation via Defender Bypass (CVE-2026-50656)

Detects successful SYSTEM-level privilege escalation via the ShieldBreak exploit, which bypasses the fix for CVE-2026-50656 (RoguePlanet) on fully patched Windows 10, 11, and Server 2025 systems while Microsoft Defender is enabled. Fires when ShieldBreak.exe spawns cmd.exe running as NT AUTHORITY\SYSTEM with a whoami/system confirmation, correlated with Defender activity on the host within a 5-minute window.