Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

48 detections

This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
avatar
Lenny Post@LennyPost
avatar
Detection & Hunting Community
2 months ago
1282189
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
1386198
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
avatar
Myron Lam@MyronLam
avatar
Detections.ai Community
2 months ago
36070
unsigned process loading both MpClient.dll and cldapi.dll in the same process instance. this is the core behavioral invariant of CVE-2026-50656 exploitation - MpClient is needed to trigger scan/remediation via RPC, cldapi provides the cloud filter callback that swaps file content mid-scan. neither DLL can be removed without breaking the exploit. with Cortex XDR as primary AV, Defender runs in passive mode and the exploit fails at scan stage, but the DLL load pattern still gets recorded by the agent. this rule detects the attempt, not the successful exploitation.
avatar
chiki briki@ekkor13
avatar
Detections.ai Community
2 months ago
16067
Detects a SYSTEM-privileged cmd.exe/powershell.exe process spawned in close temporal/process proximity to Microsoft Defender's scanning process (MsMpEng.exe), consistent with successful exploitation of the ShieldBreak zero-day (CVE-2026-50656) TOCTOU bypass. Excludes known legitimate SYSTEM shell spawns from scheduled tasks, SCCM/Intune, and PsExec-style tooling.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
21068
Detects a Windows Error Reporting (WER) crash report for MsMpEng.exe whose fault signature matches the ShieldBreak exploit crash pattern, indicating the Defender process crashed as a byproduct of the TOCTOU exploitation attempt. Excludes routine crashes tied to signature/platform updates.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
7024
Detects the compiled ShieldBreak C++ proof-of-concept exploit binary via embedded source/resource path strings and PE header, indicating local possession or execution of the CVE-2026-50656 Defender bypass PoC.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5022
Detects loading of Warden.dll — the Defender-bypass component of the ShieldBreak exploit — when unsigned or not signed by Microsoft, excluding legitimate signed Defender platform update binaries.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
10022
Detects static file artifacts bundled with the publicly released ShieldBreak Microsoft Defender exploit kit
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5019
Detects successful SYSTEM-level privilege escalation via the ShieldBreak exploit, which bypasses the fix for CVE-2026-50656 (RoguePlanet) on fully patched Windows 10, 11, and Server 2025 systems while Microsoft Defender is enabled. Fires when ShieldBreak.exe spawns cmd.exe running as NT AUTHORITY\SYSTEM with a whoami/system confirmation, correlated with Defender activity on the host within a 5-minute window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
9017
Detects registration of an unrecognized cloud sync provider combined with placeholder file creation within a short window, consistent with ShieldBreak's TOCTOU race staging technique. Excludes signed installs/re-registrations of known legitimate cloud sync clients (OneDrive, Dropbox, Google Drive, Box).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5015
Detects creation and locking of a CLFS log file matching the ShieldBreak-specific naming/path pattern, used to synchronize the exploit's TOCTOU race window against Microsoft Defender. Excludes legitimate CLFS consumers (MSMQ, TxR/TxF) and Windows servicing operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3012
Detects presence of ShieldBreak exploit project source, resource, and build files (e.g. ShieldBreak.cpp, ShieldBreak.vcxproj, shlbrk.ico) using exact known project artifact names, indicating local exploit development or PoC compilation activity.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6012
Detects ntdll.dll being copied into an alternate data stream at a ShieldBreak-specific staging path, used to prepare the overwrite of a protected system DLL. Excludes legitimate backup, imaging, and EDR/forensic tooling that streams or duplicates system DLLs.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4012
Detects Windows Defender process-level interaction consistent with the ShieldBreak exploit: MsMpEng.exe spawning an unexpected child process (excluding known-legitimate Defender helpers), or Defender's on-access scanner being triggered against unusual globalroot\BaseNamedObjects object-manager paths instead of normal filesystem paths.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1012
Detects presence of the EICAR AV test file only when co-occurring with ShieldBreak exploit artifacts (PoC binary, build files, or Warden.dll) in the same directory or process context, indicating exploit development/testing activity rather than routine AV testing.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5010
Detects network access to known repositories hosting the publicly disclosed ShieldBreak Microsoft Defender zero-day bypass PoC/tooling (GitHub, Project Nightcrawler, Church of Malware mirrors) via HTTP host/URI or TLS SNI matching.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1010
Detects DNS, HTTP, and TLS access to the public code-hosting repositories publishing the ShieldBreak Microsoft Defender 0-day exploit (GitHub, git.projectnightcrawler.dev, git.churchofmalware.org).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010
Detects network retrieval of the ShieldBreak exploit PoC or the UnDefend companion tool from their known distribution infrastructure (git.projectnightcrawler.dev, github.com/Nightmare-Eclipse/UnDefend) via TLS SNI or HTTP host/URI matching.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
109
Detects the ShieldBreak Defender-scan TOCTOU exploit locking an alternate data stream on the protected system DLL phoneinfo.dll immediately prior to an arbitrary write — the core privilege-escalation primitive of CVE-2026-50656. Excludes legitimate Windows Update/servicing operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
408
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Page 1 of 3