Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

48 detections

Detects execution of whoami.exe as NT AUTHORITY\SYSTEM within a short window of, and parented by, a suspicious SYSTEM-privileged shell spawn — a common post-exploitation confirmation step following successful ShieldBreak exploitation. Standalone whoami execution is excluded by design.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
Detects the full technical staging sequence unique to the ShieldBreak CLFS time-of-check-to-time-of-use (TOCTOU) technique: cloud provider registration, WD_TARGET/WD_SHADOW object-manager directory creation, WD_SCAN object-link creation under the normal and CLFS namespaces, ntdll.dll copy into a BERLIN alternate data stream, the link-deletion/CLFS-log-lock race sequence, and the final phoneinfo.dll:stream lock confirming the file-overwrite primitive succeeded.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
406
Detects creation of restricted object manager namespace objects (WD_TARGET_/WD_SHADOW_/WD_SCAN) used to hijack Microsoft Defender's on-access scan target as part of the ShieldBreak exploit, excluding objects created by signed Microsoft/Defender processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
202
This rule detects potential Local Privilege Escalation (LPE) activity related to a threat dubbed 'Rogue Planet'. It monitors for the creation of temporary files in the local AppData directory with a 'RP_' prefix and the usage of a specific named pipe named 'RoguePlanet'. The rule further isolates suspicious behavior by identifying processes that are not the standard Windows Error Reporting Manager (wermgr.exe) executing from its legitimate path.
avatar
Andrea Cuore@ZeroDayGlow
avatar
Detections.ai Community
3 months ago
5043
Detects Microsoft Defender service (MsMpEng.exe) spawning common interactive or scripting processes (such as cmd.exe, powershell.exe, etc.) while running as SYSTEM. This behavior is highly irregular for an antivirus engine and is characteristic of exploit-based process hollowing or quarantine pipeline abuse, as observed in CVE-2026-50656.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
64054
Detects the creation of an NTFS Alternate Data Stream named :WDFOO in temporary staging directories, often associated with wermgr.exe and subsequent Windows Defender scans. This behavior is indicative of a TOCTOU (Time-of-Check Time-of-Use) exploitation chain, specifically linked to the RoguePlanet exploit targeting CVE-2026-50656, where EICAR test strings are used to manipulate anti-virus detection flows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
15041
Detects the creation of working directories in temporary locations matching the RoguePlanet exploit staging pattern, specifically associated with CVE-2026-50656 (Nightmare Eclipse). The rule identifies the creation of directories containing fake System32 subdirectories or suspicious files (wermgr.exe) used in a TOCTOU (Time-of-Check Time-of-Use) exploit chain against MsMpEng.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
23038
Detects the creation of or connection to the specific named pipe '\\pipe\\RoguePlanet', which is used as a synchronization and callback channel by the Nightmare Eclipse RoguePlanet exploit (CVE-2026-50656). This exploit leverages the named pipe to facilitate communication between a low-privileged exploit process and a SYSTEM-level Windows Error Reporting (WER) task payload during a local privilege escalation attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
1015
Detects the creation of the named pipe '\pipe\RoguePlanet', which is specifically utilized by the RoguePlanet CVE-2026-50656 exploit. The exploit uses this pipe for synchronization during a TOCTOU race condition against MsMpEng.exe. Once the race is won, a SYSTEM-level payload (typically masquerading as a child process of wermgr.exe) uses this pipe to verify the originating session and subsequently spawn an interactive shell as NT AUTHORITY\SYSTEM. This pipe name is unique to this exploit and not used by legitimate software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
2013
Detects unauthorized child process creation by the Windows Error Reporting Manager (wermgr.exe). The rule identifies scenarios where wermgr.exe, executed under the SYSTEM context via the QueueReporting scheduled task (often abused in the RoguePlanet exploit chain), spawns interactive shells or command processors like cmd.exe, powershell.exe, or cscript.exe. Legitimate instances of wermgr.exe do not spawn interactive user interfaces or shells.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
6011
Detects the abuse of the Windows Error Reporting (WER) service mechanism, specifically targeting the 'QueueReporting' scheduled task. Attackers may employ junction-based path redirection to execute a malicious wermgr.exe binary located outside of the standard system directory. The rule identifies instances where wermgr.exe is running from non-standard locations, or running at SYSTEM integrity level spawned by standard task-related parent processes, which indicates a potential privilege escalation or persistence attempt (linked to CVE-2026-50656).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
4010
Detects instances where wermgr.exe, typically used for Windows Error Reporting (WER), spawns interactive command-line interfaces such as cmd.exe, powershell.exe, or others. This behavior is indicative of exploitation (such as CVE-2026-50656) where an attacker has redirected a scheduled task to execute malicious code under SYSTEM integrity, masquerading as the wermgr.exe process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
309
Detects the creation of specific staging directories prefixed with 'RP_' in user temporary directories, containing 'System32' or 'wdtest_temp' subdirectories. This pattern is characteristic of an NTFS junction swap exploitation technique used to target Windows Defender quarantine artifact placement as part of the CVE-2026-50656 vulnerability.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
309
Detects unauthorized execution of wermgr.exe from suspicious paths or spawned by Task Scheduler service (svchost.exe/taskeng.exe) with non-standard parent processes. This behavior is indicative of privilege escalation attempts where an unprivileged process leverages the Windows Error Reporting (WER) QueueReporting scheduled task to execute a malicious payload in the context of the SYSTEM account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
307
Detects activity associated with the RoguePlanet exploit, which involves creating EICAR content and NTFS Alternate Data Streams (ADS) within specific staging directories (wdtest_temp or RP_<UUID>). This behavior is intended to trigger Windows Defender scans and induce a TOCTOU race condition (CVE-2026-50656) by manipulating file operations near the wermgr.exe process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
106
Detects malicious activity related to the 'RoguePlanet' exploit (referencing CVE-2026-50656) which involves manipulating NTFS junctions to redirect system file operations. The rule monitors for specific staging directory patterns (RP_<UUID>), the creation of named pipes associated with RoguePlanet, and the execution of suspicious binaries or staging of files in system paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
206
Detects unauthorized processes attempting to access 'wermgr.exe' via a Volume Shadow Copy Service (VSS) device path. This behavior is associated with the RoguePlanet exploit chain (CVE-2026-50656), which leverages VSS to bypass file system protections for TOCTOU (Time-of-Check to Time-of-Use) exploitation. Legitimate system and backup processes are excluded.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
405
Detects the spawning of conhost.exe as a child process of wermgr.exe, an anomalous behavior indicative of the RoguePlanet exploit chain (CVE-2026-50656) which uses a Defender quarantine pipeline junction hijack to replace the legitimate Windows Error Reporting manager. Standard operations of the legitimate wermgr.exe process do not involve launching interactive console hosts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
205
Detects the execution of interactive shell or scripting processes (e.g., cmd.exe, powershell.exe, wscript.exe) directly or indirectly spawned by the Microsoft Defender service (MsMpEng.exe). The rule identifies processes running at SYSTEM integrity in an interactive user session, which is indicative of a TOCTOU exploit against the Defender quarantine pipeline.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
004
Detects the creation of an NTFS Alternate Data Stream (ADS) named :WDFOO on the wermgr.exe process within RP_* staged directories. This behavior is a specific indicator of the RoguePlanet exploit (CVE-2026-50656), which leverages an ADS write to trigger a Microsoft Defender on-access scan and facilitate a TOCTOU (Time-of-Check to Time-of-Use) race condition for privilege escalation or exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
204
Detects a user-mode process attempting to set an opportunistic lock (oplock) on wermgr.exe within a Volume Shadow Copy (VSS) snapshot. This behavior is associated with the RoguePlanet exploit chain (CVE-2026-50656), which leverages VSS snapshots and file locking to trigger a TOCTOU race condition against the Microsoft Defender (MsMpEng.exe) scanner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
004
Page 2 of 3