ShieldBreak race-condition completion via phoneinfo.dll:stream lock
Detects the modification or creation of an NTFS alternate data stream (ADS) on the system file phoneinfo.dll in System32, followed by the execution of a command process within two minutes. This pattern is often associated with file-based living-off-the-land techniques where attackers hide payloads or scripts within existing file metadata to evade detection.
Microsoft Sentinel (KQL)

