ShieldBreak phoneinfo.dll ADS lock during Defender TOCTOU exploit
Detects the ShieldBreak Defender-scan TOCTOU exploit locking an alternate data stream on the protected system DLL phoneinfo.dll immediately prior to an arbitrary write — the core privilege-escalation primitive of CVE-2026-50656. Excludes legitimate Windows Update/servicing operations.
Splunk (SPL)

