ShieldBreak Exploit Spawning SYSTEM-Privileged Shell
Detects the execution of command-line shells (cmd, powershell, pwsh) running under the SYSTEM context that were initiated by or associated with a process containing 'ShieldBreak' in its filename. This behavior is indicative of a suspicious or potentially malicious process (e.g., a security bypass tool) attempting to spawn elevated shells.
Microsoft Sentinel (KQL)

