ntdll.dll copied into ADS on ShieldBreak staging directory
Detects the creation of files within a directory structure matching 'ShieldBreak_' that involve 'BERLIN:' in the file path, specifically when 'ntdll.dll' is present in either the previous filename or the initiating process command line. This pattern is indicative of specific malware behavior involving file manipulation and potential DLL sideloading or obfuscation attempts.
Microsoft Sentinel (KQL)

