ShieldBreak globalroot BaseNamedObjects Defender scan trigger

This rule detects processes or file activities involving path strings related to Windows Defender shadow scan operations, specifically targeting the 'WD_SHADOW_' and 'WD_SCAN\BERLIN' named object patterns. These artifacts are typically associated with security software internal processes or potential attempts by adversaries to interact with or monitor Windows Defender's scanning activities.