
Lenny Post
@LennyPostCompletionist
0 followers2 downloads128 copies2 likes189 views
1 detection
Filters
Last updated
All Time
Detection languages
1
Categories
1
1
1
1
1
Platforms
1
Products / Services
1
MITRE Techniques
1
1
1
1
CVEs
1
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
