Suspicious Warden.dll reference in binary (ShieldBreak DLL sideloading)
Detects Portable Executable (PE) files that reference or contain the string 'Warden.dll'. This DLL name is associated with the ShieldBreak proof-of-concept (PoC) which attempts to bypass Microsoft Defender by manipulating its defensive processes or environment.
YARA

