New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access — Suspicious CFAPI Sync Root Registration

Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.