ShieldBreak TOCTOU race: CLFS log lock and link deletion sequence
This rule detects multiple occurrences of suspicious Common Log File System (CLFS) error strings within command-line arguments of processes executed on the same device within a 5-minute window. These specific error messages are often indicative of attempts to interact with or exploit vulnerabilities within the Windows CLFS driver.
Microsoft Sentinel (KQL)

