WER crash artifact (Report.wer) generated during ShieldBreak exploitation
Detects the creation of a 'Report.wer' file, typically associated with Windows Error Reporting (WER), within a directory containing the string 'ShieldBreak'. This could indicate an attempt to utilize or manipulate WER for debugging or anti-forensic activities in non-standard locations.
Microsoft Sentinel (KQL)

