ShieldBreak exploit success message correlated with SYSTEM cmd.exe spawn in same session
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
Splunk (SPL)

