New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access — Arbitrary File Read as SYSTEM (PoC Artifacts)
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
Microsoft Sentinel (KQL)

