Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
3
3
Platforms
3
Products / Services
10,371
9,516
6,509
4,371
3,687
MITRE Techniques
2
1
1
1
CVEs
3
Detects successful SYSTEM-level privilege escalation via the ShieldBreak exploit, which bypasses the fix for CVE-2026-50656 (RoguePlanet) on fully patched Windows 10, 11, and Server 2025 systems while Microsoft Defender is enabled. Fires when ShieldBreak.exe spawns cmd.exe running as NT AUTHORITY\SYSTEM with a whoami/system confirmation, correlated with Defender activity on the host within a 5-minute window.
Detects Windows Defender process-level interaction consistent with the ShieldBreak exploit: MsMpEng.exe spawning an unexpected child process (excluding known-legitimate Defender helpers), or Defender's on-access scanner being triggered against unusual globalroot\BaseNamedObjects object-manager paths instead of normal filesystem paths.
Detects the full technical staging sequence unique to the ShieldBreak CLFS time-of-check-to-time-of-use (TOCTOU) technique: cloud provider registration, WD_TARGET/WD_SHADOW object-manager directory creation, WD_SCAN object-link creation under the normal and CLFS namespaces, ntdll.dll copy into a BERLIN alternate data stream, the link-deletion/CLFS-log-lock race sequence, and the final phoneinfo.dll:stream lock confirming the file-overwrite primitive succeeded.
