ShieldCrash: Correlated Defender WD_SHADOW scan with ShieldCrash activity
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
Microsoft Sentinel (KQL)

