avatar

Lenny Post

@LennyPost
Completionist
0 followers2 downloads128 copies2 likes189 views

1 detection

This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
avatar
Lenny Post@LennyPost
avatar
Detection & Hunting Community
2 months ago
1282189